StackRadar

CVE-2023-39325

High

Advisory

Published 11 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.038
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,886
of 17,787 indexed, latest versions
Container images
2,183
deployed by those charts
Fix available
2 of 3
affected packages

HTTP/2 rapid reset can cause excessive work in net/http

Carried by container images the latest versions of 1,886 of 17,787 indexed charts deploy, on 2,183 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+109 more1.20.102,132
OSV records
DEBIAN-CVE-2023-39325GHSA-4374-p667-p6c8GO-2023-2102
Also known as
BIT-golang-2023-39325

Charts affected

1,886 by stars
ChartLatestAffected imagesRadar Score
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
stdlib@go1.18.4
1.20.10

Open the chart page →

13,071
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.13.15
0.17.0
1.20.10

Open the chart page →

15,917
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.5
0.17.0
1.20.10

Open the chart page →

5,079
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.20.10

Open the chart page →

7,698
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.32 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

2 of the 9 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.8512bb8a21483
stdlib@go1.19.10
1.20.10
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.20.10

Open the chart page →

15,606
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.20.10

Open the chart page →

6,458
temporalglasskubeVerified publisher0.45.2-gk.11 of 14See more

temporal glasskube 0.45.2-gk.1

1 of the 14 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

16,345
gorse-enterprisegorse-io0.4.23 of 5See more

gorse-enterprise gorse-io 0.4.2

3 of the 5 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.17.0
1.20.10
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.17.0
1.20.10
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.17.0
1.20.10

Open the chart page →

4,380
meta-monitoringgrafana1.3.01 of 2See more

meta-monitoring grafana 1.3.0

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.20.10

Open the chart page →

3,556
phlaregrafana0.5.41 of 1See more

phlare grafana 0.5.4

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
grafana/phlare:0.5.1330f990cdad9
golang.org/x/net@v0.5.0
stdlib@go1.19.6
0.17.0
1.20.10

Open the chart page →

2,084
carettagroundcover0.0.163 of 3See more

caretta groundcover 0.0.16

3 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18
0.17.0
1.20.10
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.17.0
1.20.10
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.17.0
1.20.10

Open the chart page →

6,799
hawkhawk1.1.52 of 4See more

hawk hawk 1.1.5

2 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.17.9
0.17.0
1.20.10
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.20.10

Open the chart page →

13,656
guacamolehelmforgeVerified publisher1.5.21 of 5See more

guacamole helmforge 1.5.2

1 of the 5 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.20.10

Open the chart page →

8,773
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
stdlib@go1.19.6
1.20.10

Open the chart page →

4,196
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.12
0.17.0
1.20.10

Open the chart page →

6,977
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
golang.org/x/net@v0.15.0
stdlib@go1.20.4
0.17.0
1.20.10

Open the chart page →

16,532
hiverhiverVerified publisher0.1.459 of 10See more

hiver hiver 0.1.45

9 of the 10 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
hiversh/antigravity:0.1.45-microvm0e36d98402bc
stdlib@go1.19.8
1.20.10
hiversh/browser:0.1.45-microvmb5048c6342ce
stdlib@go1.19.8
1.20.10
hiversh/claude:0.1.45-microvm2fbf9f264498
stdlib@go1.19.8
1.20.10
hiversh/codex:0.1.45-microvm4f43130f51e5
stdlib@go1.19.8
1.20.10
hiversh/controller:0.1.45b0b85f8942c7
stdlib@go1.19.8
1.20.10
hiversh/copilot:0.1.45-microvm50c07b84f298
stdlib@go1.19.8
1.20.10
hiversh/node:0.1.45-alpine-microvm836a37641941
stdlib@go1.19.8
1.20.10
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
stdlib@go1.19.8
1.20.10
hiversh/python:0.1.45-3.13-alpine-microvm63a5ae179a9f
stdlib@go1.19.8
1.20.10

Open the chart page →

21,779
cratedb-adapter-v2hmdmph0.2.11 of 1See more

cratedb-adapter-v2 hmdmph 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
stdlib@go1.16.3
0.17.0
1.20.10

Open the chart page →

2,913
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
stdlib@go1.17
1.20.10

Open the chart page →

6,810
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
golang.org/x/net@v0.0.0-20210907225631-ff17edfbf26d
stdlib@go1.17.2
0.17.0
1.20.10

Open the chart page →

1,573
spoolmanideaplexusVerified publisher2.7.11 of 1See more

spoolman ideaplexus 2.7.1

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
stdlib@go1.19.8
1.20.10

Open the chart page →

1,786
ilum-coreilumOfficialVerified publisher6.7.31 of 5See more

ilum-core ilum 6.7.3

1 of the 5 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.17.0
1.20.10

Open the chart page →

3,556
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.20.10

Open the chart page →

15,749
inbucketinbucketVerified publisher2.5.01 of 1See more

inbucket inbucket 2.5.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
inbucket/inbucket:3.0.01f10a0efea69
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.1
0.17.0
1.20.10

Open the chart page →

2,167
telegraf-operatorinfluxdata1.4.01 of 1See more

telegraf-operator influxdata 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
quay.io/influxdb/telegraf-operator:v1.3.11eec10ef37cc3
stdlib@go1.18.10
1.20.10

Open the chart page →

925
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.17.0
1.20.10

Open the chart page →

10,415
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.17.0
1.20.10

Open the chart page →

10,489
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.17.0
1.20.10

Open the chart page →

10,435
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.17.0
1.20.10

Open the chart page →

10,435
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.17.0
1.20.10

Open the chart page →

10,716
istio-ratelimitistio-ratelimitVerified publisher0.0.51 of 2See more

istio-ratelimit istio-ratelimit 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:4d2efd61ede09a75a84c
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.15
0.17.0
1.20.10

Open the chart page →

1,812
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.17.13
0.17.0
1.20.10

Open the chart page →

9,318
hncjouveVerified publisher0.8.31 of 1See more

hnc jouve 0.8.3

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-multitenancy/hnc-manager:v1.1.08ab8229f6a89
golang.org/x/net@v0.3.0
stdlib@go1.20.5
0.17.0
1.20.10

Open the chart page →

1,071
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
golang.org/x/net@v0.11.0
stdlib@go1.18.7
0.17.0
1.20.10

Open the chart page →

3,369
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
stdlib@go1.20.7
1.20.10

Open the chart page →

5,234
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.20.10

Open the chart page →

5,302
giteakeyporttech0.2.102 of 4See more

gitea keyporttech 0.2.10

2 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
gitea/gitea:1.12.485416d6f65fe
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.8
0.17.0
1.20.10
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.20.10

Open the chart page →

5,408
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
stdlib@go1.20.6
1.20.10

Open the chart page →

20,424
ks-corekubeblocksVerified publisher1.1.31 of 5See more

ks-core kubeblocks 1.1.3

1 of the 5 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
kubesphere/kubectl:v1.27.1649b445b1b732
golang.org/x/net@v0.8.0
stdlib@go1.18.10
0.17.0
1.20.10

Open the chart page →

4,723
kubefedkubefed0.10.01 of 2See more

kubefed kubefed 0.10.0

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
quay.io/kubernetes-multicluster/kubefed:v0.10.0c4635c95730e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.17.0
1.20.10

Open the chart page →

2,419
kubegems-localkubegemsOfficial1.24.101 of 2See more

kubegems-local kubegems 1.24.10

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
kubegems/kubectl:latestc3b4be9a54f5
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.20
0.17.0
1.20.10

Open the chart page →

6,090
monitoringkubegems44.3.41 of 1See more

monitoring kubegems 44.3.4

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
kubegems/alertproxy:v0.4.2eaee03055329
stdlib@go1.18.10
1.20.10

Open the chart page →

741
kubernetes-stateless-chartkubernetes-stateless-chart1.0.31 of 1See more

kubernetes-stateless-chart kubernetes-stateless-chart 1.0.3

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
golang.org/x/net@v0.7.0
stdlib@go1.19.4
0.17.0
1.20.10

Open the chart page →

3,275
juicefskubesphere-stable0.16.21 of 4See more

juicefs kubesphere-stable 0.16.2

1 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.20.043978fc60798
golang.org/x/net@v0.9.0
stdlib@go1.18.10
0.17.0
1.20.10

Open the chart page →

2,489
mesherykubesphere-stable0.5.07 of 13See more

meshery kubesphere-stable 0.5.0

7 of the 13 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
layer5/meshery-app-mesh:stable-latest77d59943b3d6
golang.org/x/net@v0.2.0
stdlib@go1.19.5
0.17.0
1.20.10
layer5/meshery-consul:stable-latest25a4cc38abcd
stdlib@go1.19.13
1.20.10
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b297
stdlib@go1.13.1
0.17.0
1.20.10
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.17.0
1.20.10
layer5/meshery-nsm:stable-latestebd6a8faf21f
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.12
0.17.0
1.20.10
layer5/meshery-osm:stable-latestec898e5786c6
golang.org/x/net@v0.5.0
stdlib@go1.19.8
0.17.0
1.20.10
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.17.0
1.20.10

Open the chart page →

24,690
aws-efs-csi-driverkubesphere-testVerified publisher0.1.01 of 3See more

aws-efs-csi-driver kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.17.0
1.20.10

Open the chart page →

2,605
kube-state-metricskubestar-state-metricsVerified publisher0.1.101 of 1See more

kube-state-metrics kubestar-state-metrics 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.17.0
1.20.10

Open the chart page →

1,575
kube-vault-controllerkube-vault-controller1.2.01 of 1See more

kube-vault-controller kube-vault-controller 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.17.0
1.20.10

Open the chart page →

1,550
kubemodkubmod0.5.22 of 2See more

kubemod kubmod 0.5.2

2 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.19.11f8154f7e80c
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.18
0.17.0
1.20.10
kubemod/kubemod-crt:v1.3.0028347c9fa77
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.18.1
0.17.0
1.20.10

Open the chart page →

4,542
kubeservice-cosign-webhookkubservice-chartsVerified publisher1.1.15 of 5See more

kubeservice-cosign-webhook kubservice-charts 1.1.1

5 of the 5 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
golang.org/x/net@v0.11.0
stdlib@go1.19.12
0.17.0
1.20.10
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.17.0
1.20.10
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.17.0
1.20.10
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.17.0
1.20.10
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.17.0
1.20.10

Open the chart page →

7,087

Container images carrying it

2,183 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
istio/operator:1.10.3655eefa11c84
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.17.0
1.20.10
1
istio/operator:1.12.06cfce8a071b9
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.17.0
1.20.10
1
istio/operator:1.18.270f9d1fe5fff
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.17.0
1.20.10
1
istio/pilot:1.10.0294ca55bd1cc
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.4
0.17.0
1.20.10
1
istio/pilot:1.16.0ac0284d75ec9
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.17.0
1.20.10
1
istio/pilot:1.17.1ce9d87606701
golang.org/x/net@v0.5.0
stdlib@go1.20.1
0.17.0
1.20.10
1
istio/pilot:1.15.2db08d6963975
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.19.2
0.17.0
1.20.10
1
istio/pilot:1.10.3e7e110a421c2
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.17.0
1.20.10
1
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.13
0.17.0
1.20.10
1
istio/proxyv2:1.10.088c6c693e67a
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.4
0.17.0
1.20.10
1
istio/proxyv2:1.14.1df69c1a7af7c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.17.0
1.20.10
1
itzg/mc-router:1.16.1bb552b59fb53
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.18.4
0.17.0
1.20.10
1
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.6
0.17.0
1.20.10
1
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.17.2
0.17.0
1.20.10
1
jacobalberty/unifi:v7.1.664a3616625dda
stdlib@go1.18
1.20.10
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
stdlib@go1.20.4
1.20.10
1
jaegertracing/all-in-one:1.2942822be7888b
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.17.3
0.17.0
1.20.10
1
jaegertracing/all-in-one:1.42.07d32a4eddec7
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.17.0
1.20.10
1
jaegertracing/all-in-one:1.22.0ca6b73330616
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15.8
0.17.0
1.20.10
1
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.4
0.17.0
1.20.10
1
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.17.0
1.20.10
1
jaegertracing/jaeger-query:1.41.0b636f0f464bc
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.17.0
1.20.10
1
jdvalencia422/observabilitysec:latesta80b6e47a7b8
stdlib@go1.18.4
1.20.10
1
jfwenisch/alpine-tor:latest9e6c229f953c
golang.org/x/net@v0.0.0-20190328230028-74de082e2cca
stdlib@go1.14.6
0.17.0
1.20.10
1
jhaals/yopass:11.17.026873480863b
stdlib@go1.20.5
1.20.10
1
jhaals/yopass:11.15.16bca8d5a4914
stdlib@go1.20.5
1.20.10
1
jhaals/yopass:11.4.69516e3b3e88c
stdlib@go1.19.1
1.20.10
1
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
golang.org/x/net@v0.1.0
stdlib@go1.17.13
0.17.0
1.20.10
1
jhonbrownn/elchi-discovery:latest8f6551ecc98c
golang.org/x/net@v0.13.0
0.17.0
1
jkremser/log2rbac:v0.0.5e35cf56ef183
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.17.0
1.20.10
1
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.5
0.17.0
1.20.10
1
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.15
0.17.0
1.20.10
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
golang.org/x/net@v0.9.0
stdlib@go1.18.10
0.17.0
1.20.10
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.17.0
1.20.10
1
junktext/getting-started:1.0.5a70936c04aed
golang.org/x/net@v0.11.0
stdlib@go1.18.7
0.17.0
1.20.10
1
jupyterhub/k8s-image-awaiter:3.0.1-0.dev.git.6287.hbfb05cd6a395326989c3
stdlib@go1.18.10
1.20.10
1
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.10
0.17.0
1.20.10
1
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15
0.17.0
1.20.10
1
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.13.7
0.17.0
1.20.10
1
keptn/distributor:0.8.36bc3df9e0d6a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.17.0
1.20.10
1
keptn/distributor:0.8.472e17527a4f9
stdlib@go1.16.2
1.20.10
1
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.2
0.17.0
1.20.10
1
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
golang.org/x/net@v0.0.0-20190415100556-4a65cf94b679
stdlib@go1.14.2
0.17.0
1.20.10
1
kfirfer/scripts:0.0.2481e5c4e5d70e
stdlib@go1.17.10
1.20.10
1
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.14
0.17.0
1.20.10
1
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.7
0.17.0
1.20.10
1
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18
0.17.0
1.20.10
1
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.5
0.17.0
1.20.10
1
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.10
0.17.0
1.20.10
1
kserve/kserve-controller:v0.10.022ff858b57c1
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.17.0
1.20.10
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.