StackRadar

CVE-2024-28180

Medium

Advisory

Published 7 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
413
of 17,781 indexed, latest versions
Container images
395
deployed by those charts
Fix available
3 of 4
affected packages

Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

Carried by container images the latest versions of 413 of 17,781 indexed charts deploy, on 395 images.

Affected packageAffected versionsFixed inImages
gopkg.in/square/go-jose.v2golangv2.0.0-20180411045311-89060dee6a84, v2.2.2, v2.3.0, v2.3.1+5 moreno fix listed353
github.com/go-jose/go-jose/v3golangv3.0.0, v3.0.1, v3.0.1-0.20221117193127-916db76e8214, v3.0.23.0.368
gopkg.in/go-jose/go-jose.v2golangv2.6.12.6.33
libgpg-errorrpm1.29-1.81.29-150000.3.3.11
OSV records
GHSA-c5q2-7r4c-mv6gSUSE-SU-2024:2754-1
Also known as
GO-2024-2631

Charts affected

413 by stars
ChartLatestAffected imagesRadar Score
koptimizejaconiVerified publisher0.5.41 of 2See more

koptimize jaconi 0.5.4

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
alpine/k8s:1.27.321b24e6bf801
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

5,713
jx-app-flaggerjenkins-x0.0.51 of 2See more

jx-app-flagger jenkins-x 0.0.5

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:6.5.1befcd84da2c1
gopkg.in/square/go-jose.v2@v2.3.0
no fix listed

Open the chart page →

6,028
vaultjfrog0.25.01 of 2See more

vault jfrog 0.25.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/vault:1.14.0b2177a8bfe85
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

3,968
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

16,600
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
alpine/k8s:1.22.600ac10bcb759
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

14,801
k8svault-controllerk8svault-controller0.1.21 of 1See more

k8svault-controller k8svault-controller 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

1,885
connectkfirfer1.15.02 of 2See more

connect kfirfer 1.15.0

2 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
1password/connect-api:1.7.26aa94cf713f9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1password/connect-sync:1.7.2fe527ed9d81f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

2,786
dex-k8s-authenticatorkfirfer0.0.31 of 1See more

dex-k8s-authenticator kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

2,791
kiaekiae0.1.64 of 9See more

kiae kiae 0.1.6

4 of the 9 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
istio/pilot:1.15.2db08d6963975
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
ghcr.io/dexidp/dex:v2.35.313964b29d63e
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
ghcr.io/kiaedev/kiae:latestebd03028ff6a
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

19,168
casdoorkrzwiatrzyk1.0.01 of 1See more

casdoor krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
casbin/casdoor:v1.224.066f836ef778b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

3,649
bc-depositorykubebb0.0.31 of 1See more

bc-depository kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

1,940
bc-explorerkubebb0.0.31 of 1See more

bc-explorer kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

1,940
cluster-componentkubebb0.2.21 of 4See more

cluster-component kubebb 0.2.2

1 of the 4 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
kubebb/cert-manager-controller:v1.8.020509de4b399
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

8,160
miniokubebb5.0.101 of 2See more

minio kubebb 5.0.10

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

7,459
u4a-componentkubebb0.2.103 of 8See more

u4a-component kubebb 0.2.10

3 of the 8 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
kubebb/iam-provider:v0.2.0-202401280ba03fcee3a7
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
kubebb/oidc-server:v0.2.02b5894ef1e2f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

13,819
weaviatekubebb16.3.01 of 1See more

weaviate kubebb 16.3.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
semitechnologies/weaviate:1.19.17a00d226f063
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

1,869
argo-workflowskubeblocksVerified publisher0.40.142 of 2See more

argo-workflows kubeblocks 0.40.14

2 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.5.591b9825f09a8
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3

Open the chart page →

2,871
casdoor-helm-chartskubeblocksVerified publisher1.753.01 of 1See more

casdoor-helm-charts kubeblocks 1.753.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
casbin/casdoor:v1.753.0770ad9ec3190
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

2,299
ciliumkubeblocksVerified publisher1.15.11 of 2See more

cilium kubeblocks 1.15.1

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cilium/operator-generic:v1.15.1819c7281f5a4
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3

Open the chart page →

5,075
grafanakubeblocksVerified publisher6.59.41 of 1See more

grafana kubeblocks 6.59.4

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:10.1.11b9ca4bbc4a2
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

3,561
scrutinykubernetes-homelab-helm-chartsVerified publisher0.2.21 of 3See more

scrutiny kubernetes-homelab-helm-charts 0.2.2

1 of the 3 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/influxdb:2.8571eb4514977
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

5,500
testkube-apikubeshop2.1.1621 of 2See more

testkube-api kubeshop 2.1.162

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
kubeshop/testkube-api-server:2.1.162e97dc620d9b4
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

1,663
harborkubesphereVerified publisher1.9.32 of 11See more

harbor kubesphere 1.9.3

2 of the 11 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.5.386bf3031f4a7
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

17,798
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:9.5.239c849cebccc
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3

Open the chart page →

18,316
pulsarkubesphere-stable2.7.131 of 3See more

pulsar kubesphere-stable 2.7.13

1 of the 3 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

14,320
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

16,520
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed

Open the chart page →

3,191
op-scim-bridgelifen1.0.31 of 2See more

op-scim-bridge lifen 1.0.3

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

2,777
op-scim-bridgelifen-chartsVerified publisher1.0.31 of 2See more

op-scim-bridge lifen-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

2,777
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3

Open the chart page →

10,716
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,129
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed

Open the chart page →

4,904
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

2,101
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

7,510
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

3,225
loft-agentloftVerified publisher3.2.41 of 1See more

loft-agent loft 3.2.4

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/agent:3.2.45c109914ff73
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.5.1
3.0.3
no fix listed

Open the chart page →

2,444
loft-direct-cluster-endpointloftVerified publisher1.14.01 of 1See more

loft-direct-cluster-endpoint loft 1.14.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
loftsh/directclusterendpoint:1.14.0310cc7d690f5
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

3,112
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

3,225
vcluster-proloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

5,085
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.101 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

1 of the 4 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

5,936
vcluster-pro-k0sloftVerified publisher0.0.0-ci-run.101 of 2See more

vcluster-pro-k0s loft 0.0.0-ci-run.10

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

5,768
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.103 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

3 of the 4 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed

Open the chart page →

8,202
nightingalelogic3579Verified publisher0.3.11 of 6See more

nightingale logic3579 0.3.1

1 of the 6 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.5.1421acb36181b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

8,938
apica-ascentlogiqai2.0.41 of 19See more

apica-ascent logiqai 2.0.4

1 of the 19 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

23,613
dex-k8s-authenticatormesosphere1.4.31 of 1See more

dex-k8s-authenticator mesosphere 1.4.3

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
mesosphere/dex-k8s-authenticator:v1.4.1-d2iqf3d9982cc2fd
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed

Open the chart page →

1,019
kube-oidc-proxymesosphere0.3.41 of 1See more

kube-oidc-proxy mesosphere 0.3.4

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

3,144
traefik2mesosphere9.18.01 of 1See more

traefik2 mesosphere 9.18.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/traefik:2.4.8eda951fd29a8
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

3,341
cert-manager-setupmesosphere-stable0.2.101 of 5See more

cert-manager-setup mesosphere-stable 0.2.10

1 of the 5 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

7,179
dexmesosphere-stable2.14.12 of 5See more

dex mesosphere-stable 2.14.1

2 of the 5 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
mesosphere/dex-controller:v0.16.11b2dd9c0b0fc
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

19,214
kommandermesosphere-stable0.39.22 of 29See more

kommander mesosphere-stable 0.39.2

2 of the 29 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:6.6.0052147d7e0ec
gopkg.in/square/go-jose.v2@v2.3.0
no fix listed
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
gopkg.in/square/go-jose.v2@v2.0.0-20180411045311-89060dee6a84
no fix listed

Open the chart page →

68,284

Container images carrying it

395 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
2
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
2
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
2
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
1password/connect-api:1.7.26aa94cf713f9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
1password/connect-sync:1.7.2fe527ed9d81f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
akeyless/gateway:5.3.13d2e7dce5eb9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
alex6021710/ai-scale-saver:latestf73e8d60fd03
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
alpine/k8s:1.22.600ac10bcb759
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
alpine/k8s:1.27.321b24e6bf801
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
alpine/k8s:1.18.16a41efe02a041
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
alpine/k8s:1.28.2fc059f056ad0
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
anchore/anchore-engine:v0.10.0bde9eedf639d
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
artifacthub/hub:v1.19.0111918d8c399
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bicarus/wg-access-server:v0.8.206cab48e9334
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
casbin/casdoor:v1.224.066f836ef778b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
casbin/casdoor:v1.753.0770ad9ec3190
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
casbin/casdoor:3.62.17729da148c61
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
casbin/casdoor:3.62.0e08231f16c00
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
chaosnative/cle-auth-server:2.7.072ee352bc333
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
chirpstack/chirpstack-application-server:3fb7667fe037f
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
cloudflare/cloudflared:2023.10.0c18744ae1767
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
1
cockroachdb/cockroach-operator:v2.1.0983312754620
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
coderenvs/coder-service:1.44.61deffc4670e6
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
containous/maesh:v1.3.2587162516502
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
cortezaproject/corteza:2024.9.08eb7a26605c9
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
craftypath/sops-operator:v0.8.0402a0024c732
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
datappeal/hive-metastore:lateste38c085a3567
gopkg.in/square/go-jose.v2@v2.4.0
no fix listed
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.