StackRadar

CVE-2024-28180

Medium

Advisory

Published 7 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
413
of 17,781 indexed, latest versions
Container images
395
deployed by those charts
Fix available
3 of 4
affected packages

Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

Carried by container images the latest versions of 413 of 17,781 indexed charts deploy, on 395 images.

Affected packageAffected versionsFixed inImages
gopkg.in/square/go-jose.v2golangv2.0.0-20180411045311-89060dee6a84, v2.2.2, v2.3.0, v2.3.1+5 moreno fix listed353
github.com/go-jose/go-jose/v3golangv3.0.0, v3.0.1, v3.0.1-0.20221117193127-916db76e8214, v3.0.23.0.368
gopkg.in/go-jose/go-jose.v2golangv2.6.12.6.33
libgpg-errorrpm1.29-1.81.29-150000.3.3.11
OSV records
GHSA-c5q2-7r4c-mv6gSUSE-SU-2024:2754-1
Also known as
GO-2024-2631

Charts affected

413 by stars
ChartLatestAffected imagesRadar Score
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

8,902
wg-access-servermglants0.4.71 of 1See more

wg-access-server mglants 0.4.7

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,745
miniomilvus-helm8.0.191 of 1See more

minio milvus-helm 8.0.19

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2024-05-28T17-19-04Z391d1d45fdbe
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

1,529
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed

Open the chart page →

15,855
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

7,775
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

10,959
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3fb7667fe037f
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

25,933
cognativemyaVerified publisher0.2403.32 of 3See more

cognative mya 0.2403.3

2 of the 3 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:10.4.0f9811e4e687f
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

7,309
influxdbmy-personal-influxdb20.1.01 of 1See more

influxdb my-personal-influxdb2 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

3,867
traefik-forward-auth-openidnas-helm-chartsVerified publisher1.0.11 of 1See more

traefik-forward-auth-openid nas-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:latestb364aa6a4117
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

2,197
webspacednetsocVerified publisher0.2.81 of 2See more

webspaced netsoc 0.2.8

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

5,193
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

6,455
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

4,674
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

2,966
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

2,246
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

27,465
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3

Open the chart page →

17,070
multicluster-meshocm-helm-chartsVerified publisher0.0.21 of 1See more

multicluster-mesh ocm-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

2,124
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

5,826
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
gopkg.in/square/go-jose.v2@v2.4.0
no fix listed

Open the chart page →

8,540
one-green-coreone-green-coreVerified publisher0.0.72 of 8See more

one-green-core one-green-core 0.0.7

2 of the 8 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:8.5.3ecc1b80b8ca2
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
library/influxdb:2.0.8ba10ac9ba17a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

9,558
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

18,023
minioopenobserve5.0.71 of 2See more

minio openobserve 5.0.7

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

7,459
osm-edgeopenshift1.2.1-ubi83 of 7See more

osm-edge openshift 1.2.1-ubi8

3 of the 7 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

19,455
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

8,599
gitlab-proxyopslevelVerified publisher0.0.81 of 1See more

gitlab-proxy opslevel 0.0.8

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/caddy:2.660fb54d36b4b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

1,872
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed

Open the chart page →

71,208
osm-edgeosm-edgeVerified publisher1.3.93 of 7See more

osm-edge osm-edge 1.3.9

3 of the 7 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
flomesh/osm-edge-controller:1.3.9add7a4da4622
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
flomesh/osm-edge-injector:1.3.947287e3ad324
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

5,589
parcaparca4.19.01 of 2See more

parca parca 4.19.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3

Open the chart page →

3,350
parcaparca-chart0.1.01 of 1See more

parca parca-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3

Open the chart page →

1,978
archive-analysispcp-helm-chartsVerified publisher1.0.11 of 1See more

archive-analysis pcp-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/performancecopilot/archive-analysis:latest8de11e2363fc
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

1,326
npre-essentialsphntom0.1.602 of 22See more

npre-essentials phntom 0.1.60

2 of the 22 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
phntom/oauth2-proxy:v7.3.48ea656a2a895
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
quay.io/groundcover/grafana:9.3.18c65b333a3d3
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

26,840
firehose-corepinaxVerified publisher0.1.11 of 2See more

firehose-core pinax 0.1.1

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

3,488
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

7,062
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

4,889
virtual-workspacesplatform-mesh-virtual-workspaces0.13.01 of 1See more

virtual-workspaces platform-mesh-virtual-workspaces 0.13.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/platform-mesh/platform-mesh/virtual-workspaces:v0.17.0bb2ee6241719
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

23
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
gopkg.in/square/go-jose.v2@v2.4.0
no fix listed

Open the chart page →

9,606
oauth2-proxypresto-loadbalancer4.3.181 of 2See more

oauth2-proxy presto-loadbalancer 4.3.18

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed

Open the chart page →

3,958
prometheus-optimizerprometheus-optimizer0.2.221 of 1See more

prometheus-optimizer prometheus-optimizer 0.2.22

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3

Open the chart page →

4,416
cdmswebapppyalive-cdmswebappVerified publisher0.1.01 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
sarwansharma/minio:v359d1da9385d1
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

6,668
quarksquarks7.0.1+0.g5396b111 of 5See more

quarks quarks 7.0.1+0.g5396b11

1 of the 5 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/cfcontainerizationbot/kubecf-kubectl:v1.19.261daa1bba5cb
libgpg-error@1.29-1.8
1.29-150000.3.3.1

Open the chart page →

18,197
influxdbquench-influxdbVerified publisher0.0.131 of 1See more

influxdb quench-influxdb 0.0.13

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/influxdbdigest-pinned49591c907fa2
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

78
hydraradar-baseVerified publisher0.48.01 of 1See more

hydra radar-base 0.48.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
oryd/hydra:v2.2.02c93beb5e5f2
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3

Open the chart page →

1,524
kratosradar-baseVerified publisher0.43.11 of 1See more

kratos radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
oryd/kratos:v1.1.08f15006a080d
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3

Open the chart page →

1,776
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/go-jose/go-jose.v2@v2.6.1
3.0.3
2.6.3

Open the chart page →

16,047
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

29,227
argocdromholdings1.8.12 of 3See more

argocd romholdings 1.8.1

2 of the 3 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
quay.io/dexidp/dex:v2.25.07bcf286807b8
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed

Open the chart page →

10,466
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

6,237
devtron-enterpriseromholdings48.0.03 of 28See more

devtron-enterprise romholdings 48.0.0

3 of the 28 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
quay.io/devtron/dex:v2.30.22e4c14d1b444
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
quay.io/devtron/kubectl:latest2ad610626658
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

68,240
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

5,039

Container images carrying it

395 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
2
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
2
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
2
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
1password/connect-api:1.7.26aa94cf713f9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
1password/connect-sync:1.7.2fe527ed9d81f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
akeyless/gateway:5.3.13d2e7dce5eb9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
alex6021710/ai-scale-saver:latestf73e8d60fd03
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
alpine/k8s:1.22.600ac10bcb759
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
alpine/k8s:1.27.321b24e6bf801
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
alpine/k8s:1.18.16a41efe02a041
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
alpine/k8s:1.28.2fc059f056ad0
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
anchore/anchore-engine:v0.10.0bde9eedf639d
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
artifacthub/hub:v1.19.0111918d8c399
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bicarus/wg-access-server:v0.8.206cab48e9334
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
casbin/casdoor:v1.224.066f836ef778b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
casbin/casdoor:v1.753.0770ad9ec3190
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
casbin/casdoor:3.62.17729da148c61
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
casbin/casdoor:3.62.0e08231f16c00
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
chaosnative/cle-auth-server:2.7.072ee352bc333
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
chirpstack/chirpstack-application-server:3fb7667fe037f
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
cloudflare/cloudflared:2023.10.0c18744ae1767
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
1
cockroachdb/cockroach-operator:v2.1.0983312754620
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
coderenvs/coder-service:1.44.61deffc4670e6
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
containous/maesh:v1.3.2587162516502
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
cortezaproject/corteza:2024.9.08eb7a26605c9
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
craftypath/sops-operator:v0.8.0402a0024c732
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
datappeal/hive-metastore:lateste38c085a3567
gopkg.in/square/go-jose.v2@v2.4.0
no fix listed
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.