StackRadar

CVE-2025-21614

High

Advisory

Published 6 Jan 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
113
of 17,781 indexed, latest versions
Container images
110
deployed by those charts
Fix available
1 of 2
affected packages

go-git clients vulnerable to DoS via maliciously crafted Git server replies

Carried by container images the latest versions of 113 of 17,781 indexed charts deploy, on 110 images.

Affected packageAffected versionsFixed inImages
github.com/go-git/go-git/v5golangv5.0.0, v5.1.0, v5.2.0, v5.3.0+9 more5.13.097
gopkg.in/src-d/go-git.v4golangv4.10.0, v4.13.1no fix listed16
OSV records
GHSA-r9px-m959-cxf4
Also known as
GO-2025-3367

Charts affected

113 by stars
ChartLatestAffected imagesRadar Score
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

10,134
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

10,902
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

1,360
agentssynapse0.1.303 of 9See more

agents synapse 0.1.30

3 of the 9 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/go-git/go-git/v5@v5.5.2
5.13.0
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.13.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/go-git/go-git/v5@v5.5.2
5.13.0

Open the chart page →

7,244
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/go-git/go-git/v5@v5.5.2
5.13.0

Open the chart page →

1,815
explorersynapse0.2.162 of 6See more

explorer synapse 0.2.16

2 of the 6 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/go-git/go-git/v5@v5.12.0
5.13.0
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

8,518
omnirpcsynapse0.2.921 of 2See more

omnirpc synapse 0.2.92

1 of the 2 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

1,121
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/go-git/go-git/v5@v5.5.2
5.13.0

Open the chart page →

1,704
screenersynapse0.2.51 of 4See more

screener synapse 0.2.5

1 of the 4 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/screener-api:latestb3de2050460a
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

1,091
scribesynapse0.2.162 of 7See more

scribe synapse 0.2.16

2 of the 7 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.13.0
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

1,955
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

2,477
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

4,086

Container images carrying it

110 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
grafana/grafana:10.1.11b9ca4bbc4a2
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
grafana/grafana:9.5.239c849cebccc
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
grafana/grafana:9.4.376dcf36e7d2a
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
grafana/grafana:9.1.19746858c20e6
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
hashicorp/waypoint:0.11.397d521a27498
github.com/go-git/go-git/v5@v5.2.0
gopkg.in/src-d/go-git.v4@v4.13.1
5.13.0
no fix listed
1
inseefrlab/shelly:cloudshell31f04ca7436b
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
invisibl/gravity-init:v1.0.91a970f84178b
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
iotaledger/goshimmer:v0.8.6b02a8f77474f
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
kubebb/oidc-server:v0.2.02b5894ef1e2f
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
kusionstack/kusion:v0.14.0126c8f0b0976
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
layer5/meshery-consul:stable-latest25a4cc38abcd
github.com/go-git/go-git/v5@v5.9.0
5.13.0
1
layer5/meshery-linkerd:stable-latestb99c73bac1f5
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
layer5/meshery-osm:stable-latestec898e5786c6
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
github.com/go-git/go-git/v5@v5.2.0
gopkg.in/src-d/go-git.v4@v4.13.1
5.13.0
no fix listed
1
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
ntakashi/gitana:1.4.04171ec641120
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
owncloud/ocis:1.7.0d2efcae92c84
github.com/go-git/go-git/v5@v5.1.0
5.13.0
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
github.com/go-git/go-git/v5@v5.3.0
5.13.0
1
semaphoreui/semaphore:v2.9.645b50bc11833f
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
sikalabs/slu:v0.72.07bd267f30247
github.com/go-git/go-git/v5@v5.8.1
5.13.0
1
sikalabs/slu:v0.34.0fdc0c6711add
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
stakater/whitelister:v0.0.1639107924063e
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
stakater/workshop-operator:v0.0.3897bf456cc97c
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/go-git/go-git/v5@v5.7.0
5.13.0
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
github.com/go-git/go-git/v5@v5.7.0
5.13.0
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
github.com/go-git/go-git/v5@v5.2.0
5.13.0
1
ghcr.io/openclarity/grype-server:v0.6.079412399f301
github.com/go-git/go-git/v5@v5.8.1
5.13.0
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/go-git/go-git/v5@v5.5.2
5.13.0
1
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/go-git/go-git/v5@v5.5.2
5.13.0
1
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/go-git/go-git/v5@v5.5.2
5.13.0
1
ghcr.io/synapsecns/sanguine/screener-api:latestb3de2050460a
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/go-git/go-git/v5@v5.5.2
5.13.0
1
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
github.com/go-git/go-git/v5@v5.12.0
5.13.0
1
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/go-git/go-git/v5@v5.4.2
5.13.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.