StackRadar

CVE-2024-28180

Medium

Advisory

Published 7 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
413
of 17,781 indexed, latest versions
Container images
395
deployed by those charts
Fix available
3 of 4
affected packages

Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

Carried by container images the latest versions of 413 of 17,781 indexed charts deploy, on 395 images.

Affected packageAffected versionsFixed inImages
gopkg.in/square/go-jose.v2golangv2.0.0-20180411045311-89060dee6a84, v2.2.2, v2.3.0, v2.3.1+5 moreno fix listed353
github.com/go-jose/go-jose/v3golangv3.0.0, v3.0.1, v3.0.1-0.20221117193127-916db76e8214, v3.0.23.0.368
gopkg.in/go-jose/go-jose.v2golangv2.6.12.6.33
libgpg-errorrpm1.29-1.81.29-150000.3.3.11
OSV records
GHSA-c5q2-7r4c-mv6gSUSE-SU-2024:2754-1
Also known as
GO-2024-2631

Charts affected

413 by stars
ChartLatestAffected imagesRadar Score
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

8,902
wg-access-servermglants0.4.71 of 1See more

wg-access-server mglants 0.4.7

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,745
miniomilvus-helm8.0.191 of 1See more

minio milvus-helm 8.0.19

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2024-05-28T17-19-04Z391d1d45fdbe
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

1,529
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed

Open the chart page →

15,855
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

7,775
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

10,959
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3fb7667fe037f
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

25,933
cognativemyaVerified publisher0.2403.32 of 3See more

cognative mya 0.2403.3

2 of the 3 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:10.4.0f9811e4e687f
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

7,309
influxdbmy-personal-influxdb20.1.01 of 1See more

influxdb my-personal-influxdb2 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

3,867
traefik-forward-auth-openidnas-helm-chartsVerified publisher1.0.11 of 1See more

traefik-forward-auth-openid nas-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:latestb364aa6a4117
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

2,197
webspacednetsocVerified publisher0.2.81 of 2See more

webspaced netsoc 0.2.8

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

5,193
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

6,455
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

4,674
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

2,966
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

2,246
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

27,465
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3

Open the chart page →

17,070
multicluster-meshocm-helm-chartsVerified publisher0.0.21 of 1See more

multicluster-mesh ocm-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

2,124
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

5,826
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
gopkg.in/square/go-jose.v2@v2.4.0
no fix listed

Open the chart page →

8,540
one-green-coreone-green-coreVerified publisher0.0.72 of 8See more

one-green-core one-green-core 0.0.7

2 of the 8 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:8.5.3ecc1b80b8ca2
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
library/influxdb:2.0.8ba10ac9ba17a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

9,558
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

18,023
minioopenobserve5.0.71 of 2See more

minio openobserve 5.0.7

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

7,459
osm-edgeopenshift1.2.1-ubi83 of 7See more

osm-edge openshift 1.2.1-ubi8

3 of the 7 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

19,455
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

8,599
gitlab-proxyopslevelVerified publisher0.0.81 of 1See more

gitlab-proxy opslevel 0.0.8

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/caddy:2.660fb54d36b4b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

1,872
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed

Open the chart page →

71,208
osm-edgeosm-edgeVerified publisher1.3.93 of 7See more

osm-edge osm-edge 1.3.9

3 of the 7 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
flomesh/osm-edge-controller:1.3.9add7a4da4622
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
flomesh/osm-edge-injector:1.3.947287e3ad324
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

5,589
parcaparca4.19.01 of 2See more

parca parca 4.19.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3

Open the chart page →

3,350
parcaparca-chart0.1.01 of 1See more

parca parca-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3

Open the chart page →

1,978
archive-analysispcp-helm-chartsVerified publisher1.0.11 of 1See more

archive-analysis pcp-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/performancecopilot/archive-analysis:latest8de11e2363fc
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed

Open the chart page →

1,326
npre-essentialsphntom0.1.602 of 22See more

npre-essentials phntom 0.1.60

2 of the 22 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
phntom/oauth2-proxy:v7.3.48ea656a2a895
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
quay.io/groundcover/grafana:9.3.18c65b333a3d3
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

26,840
firehose-corepinaxVerified publisher0.1.11 of 2See more

firehose-core pinax 0.1.1

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

3,488
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

7,062
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

4,889
virtual-workspacesplatform-mesh-virtual-workspaces0.13.01 of 1See more

virtual-workspaces platform-mesh-virtual-workspaces 0.13.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/platform-mesh/platform-mesh/virtual-workspaces:v0.17.0bb2ee6241719
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

23
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
gopkg.in/square/go-jose.v2@v2.4.0
no fix listed

Open the chart page →

9,606
oauth2-proxypresto-loadbalancer4.3.181 of 2See more

oauth2-proxy presto-loadbalancer 4.3.18

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed

Open the chart page →

3,958
prometheus-optimizerprometheus-optimizer0.2.221 of 1See more

prometheus-optimizer prometheus-optimizer 0.2.22

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3

Open the chart page →

4,416
cdmswebapppyalive-cdmswebappVerified publisher0.1.01 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
sarwansharma/minio:v359d1da9385d1
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

6,668
quarksquarks7.0.1+0.g5396b111 of 5See more

quarks quarks 7.0.1+0.g5396b11

1 of the 5 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/cfcontainerizationbot/kubecf-kubectl:v1.19.261daa1bba5cb
libgpg-error@1.29-1.8
1.29-150000.3.3.1

Open the chart page →

18,197
influxdbquench-influxdbVerified publisher0.0.131 of 1See more

influxdb quench-influxdb 0.0.13

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/influxdbdigest-pinned49591c907fa2
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

78
hydraradar-baseVerified publisher0.48.01 of 1See more

hydra radar-base 0.48.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
oryd/hydra:v2.2.02c93beb5e5f2
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3

Open the chart page →

1,524
kratosradar-baseVerified publisher0.43.11 of 1See more

kratos radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
oryd/kratos:v1.1.08f15006a080d
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3

Open the chart page →

1,776
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/go-jose/go-jose.v2@v2.6.1
3.0.3
2.6.3

Open the chart page →

16,047
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

29,227
argocdromholdings1.8.12 of 3See more

argocd romholdings 1.8.1

2 of the 3 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
quay.io/dexidp/dex:v2.25.07bcf286807b8
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed

Open the chart page →

10,466
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

6,237
devtron-enterpriseromholdings48.0.03 of 28See more

devtron-enterprise romholdings 48.0.0

3 of the 28 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
quay.io/devtron/dex:v2.30.22e4c14d1b444
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
quay.io/devtron/kubectl:latest2ad610626658
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

68,240
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

5,039

Container images carrying it

395 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
hashicorp/consul:1.15.3ddff34041c5c
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hashicorp/vault:1.15.40b01ed3924e6
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
hashicorp/vault:1.14.0b2177a8bfe85
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
hashicorp/vault:1.8.4dfc3500beb0e
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hashicorp/waypoint:0.11.397d521a27498
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
igrantio/bb-consent-api:2023.12.22d2ea6546ffe
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
1
inseefrlab/shelly:cloudshell31f04ca7436b
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
intel/multimodal-data-visualization:3.03426deb77337
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
ipfs/go-ipfs:v0.13.117259397f587
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
ipfs/kubo:v0.17.0803fac58ba15
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
ipfs/kubo:v0.24.0e3de33bd746b
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
istio/operator:1.10.3655eefa11c84
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
istio/operator:1.12.06cfce8a071b9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
istio/operator:1.18.270f9d1fe5fff
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
istio/pilot:1.10.0294ca55bd1cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
istio/pilot:1.16.0ac0284d75ec9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
istio/pilot:1.17.1ce9d87606701
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
istio/pilot:1.15.2db08d6963975
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
istio/pilot:1.10.3e7e110a421c2
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
istio/proxyv2:1.9.687a9db561d2e
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
istio/proxyv2:1.10.088c6c693e67a
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
istio/proxyv2:1.14.1df69c1a7af7c
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
kubebb/cert-manager-controller:v1.8.020509de4b399
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
kubebb/iam-provider:v0.2.0-202401280ba03fcee3a7
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
kubebb/oidc-server:v0.2.02b5894ef1e2f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
kubebuilder/kube-rbac-proxy:v0.16.03c4f708c6204
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
kubernetesui/dashboard:v2.6.1290bebc3cd96
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
kubernetesui/dashboard:v2.7.02e500d29e9d5
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
kubeshop/testkube-api-server:2.1.162e97dc620d9b4
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
kubevious/ui:1.2.16233e84bdd59
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
1
kusionstack/karpor:v0.6.4b707d3bf0abd
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
1
library/caddy:2.660fb54d36b4b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
library/caddy:2.2.0-alpine7367adca165f
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
library/caddy:2.4.5874405536b3e
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
library/caddy:2.4.2-alpinefbc51bcf1ab0
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
library/influxdb:2.8571eb4514977
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
library/influxdb:2.7.4-alpinea10d46445d68
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
library/influxdb:2.0.8ba10ac9ba17a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
library/influxdb:2.3.0-alpined7f5dd5f70e2
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.