StackRadar

CVE-2025-21613

Critical

Advisory

Published 6 Jan 2025In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
113
of 17,781 indexed, latest versions
Container images
110
deployed by those charts
Fix available
1 of 2
affected packages

go-git has an Argument Injection via the URL field

Carried by container images the latest versions of 113 of 17,781 indexed charts deploy, on 110 images.

Affected packageAffected versionsFixed inImages
github.com/go-git/go-git/v5golangv5.0.0, v5.1.0, v5.2.0, v5.3.0+9 more5.13.097
gopkg.in/src-d/go-git.v4golangv4.10.0, v4.13.1no fix listed16
OSV records
GHSA-v725-9546-7q7m
Also known as
GO-2025-3368

Charts affected

113 by stars
ChartLatestAffected imagesRadar Score
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

10,134
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

10,902
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

1,360
agentssynapse0.1.303 of 9See more

agents synapse 0.1.30

3 of the 9 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/go-git/go-git/v5@v5.5.2
5.13.0
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.13.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/go-git/go-git/v5@v5.5.2
5.13.0

Open the chart page →

7,244
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/go-git/go-git/v5@v5.5.2
5.13.0

Open the chart page →

1,815
explorersynapse0.2.162 of 6See more

explorer synapse 0.2.16

2 of the 6 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/go-git/go-git/v5@v5.12.0
5.13.0
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

8,518
omnirpcsynapse0.2.921 of 2See more

omnirpc synapse 0.2.92

1 of the 2 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

1,121
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/go-git/go-git/v5@v5.5.2
5.13.0

Open the chart page →

1,704
screenersynapse0.2.51 of 4See more

screener synapse 0.2.5

1 of the 4 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/screener-api:latestb3de2050460a
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

1,091
scribesynapse0.2.162 of 7See more

scribe synapse 0.2.16

2 of the 7 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.13.0
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

1,955
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

2,477
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2025-21613.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

4,086

Container images carrying it

110 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/dex:v2.30.22e4c14d1b444
github.com/go-git/go-git/v5@v5.2.0
5.13.0
6
quay.io/devtron/kubectl:latest2ad610626658
github.com/go-git/go-git/v5@v5.4.2
5.13.0
6
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.13.0
4
argoproj/argocd:v1.8.1830e86cacefd
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/go-git/go-git/v5@v5.7.0
5.13.0
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/go-git/go-git/v5@v5.6.1
5.13.0
3
datawire/aes:1.14.48588eafe6862
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
2
grafana/grafana:9.2.4057896e23443
github.com/go-git/go-git/v5@v5.4.2
5.13.0
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
github.com/go-git/go-git/v5@v5.1.0
5.13.0
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/go-git/go-git/v5@v5.4.2
5.13.0
2
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
github.com/go-git/go-git/v5@v5.2.0
5.13.0
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/go-git/go-git/v5@v5.4.2
5.13.0
2
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
github.com/go-git/go-git/v5@v5.0.0
5.13.0
1
aquasec/trivy:0.43.1944a04445179
github.com/go-git/go-git/v5@v5.7.0
5.13.0
1
aquasec/trivy:0.32.0973d0df16189
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
artifacthub/hub:v1.19.0111918d8c399
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
buddyspencer/gickup:0.10.309e7dbf923c12
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
casbin/casdoor:v1.753.0770ad9ec3190
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
chaosnative/cle-server:2.7.0e7bcff4a20c0
github.com/go-git/go-git/v5@v5.3.0
5.13.0
1
charmcli/soft-serve:v0.4.039523c1a6ba8
github.com/go-git/go-git/v5@v5.4.3-0.20210630082519-b4368b2a2ca4
5.13.0
1
datappeal/hive-metastore:lateste38c085a3567
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
datawire/aes:1.13.62beb65062c8b
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
datawire/aes:3.11.195ec30b3c732
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
devopstales/trivy-operator:2.575136aa7a26e
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
devspacecloud/manager:0.3.349c397413f7b
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
dexidp/dex:v2.39.1-distroless43655afd1a8f
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
github.com/go-git/go-git/v5@v5.4.3-0.20210630082519-b4368b2a2ca4
5.13.0
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
gopkg.in/src-d/go-git.v4@v4.10.0
no fix listed
1
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
epamedp/reconciler:2.12.0d33e938b6d59
github.com/go-git/go-git/v5@v5.4.3-0.20210630082519-b4368b2a2ca4
5.13.0
1
flanksource/apm-hub:v0.0.471dacc3195bf9
github.com/go-git/go-git/v5@v5.6.1
5.13.0
1
fluxcd/source-controller:v0.10.031a8c79a6803
github.com/go-git/go-git/v5@v5.2.0
5.13.0
1
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
gitea/act_runner:0.2.11c57233403eff
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
gitea/gitea:1.22.376f516a1a8c2
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
gitea/gitea:1.12.485416d6f65fe
github.com/go-git/go-git/v5@v5.1.0
5.13.0
1
gitea/gitea:1.21.6ac73e0da341f
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
gitea/gitea:1.13.0d5ab14cd29af
github.com/go-git/go-git/v5@v5.1.0
5.13.0
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/go-git/go-git/v5@v5.7.0
5.13.0
1
grafana/agent:v0.40.3f6cbec9409be
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
grafana/alloy:v1.5.101a63f4e032c
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
grafana/alloy:v1.4.306bdcbb51fc2
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
grafana/alloy:v1.1.1c3dac4e26471
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
grafana/grafana:10.1.50679e877ba20
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
grafana/grafana:9.4.71a359d92f40e
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.