CVE-2025-22868
HighAdvisory
Published 26 Feb 2025In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.009
- 57th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,717
- of 17,832 indexed, latest versions
- Container images
- 2,081
- deployed by those charts
- Fix available
- 1 of 1
- affected package
golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability
Carried by container images the latest versions of 1,717 of 17,832 indexed charts deploy, on 2,081 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more | 0.27.0 | 2,081 |
- OSV records
- GHSA-6v2p-p543-phr9
- Also known as
- GO-2025-3488
Charts affected
1,717 by stars
Container images carrying it
2,081 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| chirpstack/ | e0b23dfd24d6 | golang.org/ | 0.27.0 | 1 |
| chirpstack/ | fb7667fe037f | golang.org/ | 0.27.0 | 1 |
| chirpstack/ | c0bbbb7a3f1e | golang.org/ | 0.27.0 | 1 |
| chirpstack/ | c98d7fe06bce | golang.org/ | 0.27.0 | 1 |
| chrislusf/ | 634b094b2183 | golang.org/ | 0.27.0 | 1 |
| chrislusf/ | db095fe8a8d6 | golang.org/ | 0.27.0 | 1 |
| chrislusf/ | ed80f00fde46 | golang.org/ | 0.27.0 | 1 |
| chriswells0/ | f3918ec8471c | golang.org/ | 0.27.0 | 1 |
| circleci/ | 4d8d0ae5efc3 | golang.org/ | 0.27.0 | 1 |
| ciscolabs/ | 36d02faad958 | golang.org/ | 0.27.0 | 1 |
| clastix/ | 43d301afbca8 | golang.org/ | 0.27.0 | 1 |
| cloudbees/ | 1d44fb4f799b | golang.org/ | 0.27.0 | 1 |
| cloudbees/ | 8f102ef0383a | golang.org/ | 0.27.0 | 1 |
| cloudentity/ | 9402ec4b5016 | golang.org/ | 0.27.0 | 1 |
| cloudentity/ | 8a1890eb8265 | golang.org/ | 0.27.0 | 1 |
| cloudentity/ | ee83cdd45b7b | golang.org/ | 0.27.0 | 1 |
| cloudentity/ | 5728654cecb7 | golang.org/ | 0.27.0 | 1 |
| cloudentity/ | 8ca94ae6acf4 | golang.org/ | 0.27.0 | 1 |
| cloudentity/ | c04eb10c77b7 | golang.org/ | 0.27.0 | 1 |
| cloudflare/ | 14d9c6b01b29 | golang.org/ | 0.27.0 | 1 |
| cloudflare/ | 5d5f70a59d5e | golang.org/ | 0.27.0 | 1 |
| cloudflare/ | 665dda65335e | golang.org/ | 0.27.0 | 1 |
| cloudflare/ | c18744ae1767 | golang.org/ | 0.27.0 | 1 |
| cloudnativelabs/ | 0ec7cd73f43f | golang.org/ | 0.27.0 | 1 |
| cmacrae/ | dec8d490fe40 | golang.org/ | 0.27.0 | 1 |
| cockroachdb/ | 983312754620 | golang.org/ | 0.27.0 | 1 |
| conduction/ | 9cfeeb6c7c20 | golang.org/ | 0.27.0 | 1 |
| conduction/ | c36094a41369 | golang.org/ | 0.27.0 | 1 |
| conduction/ | ece1ab544c57 | golang.org/ | 0.27.0 | 1 |
| conduction/ | 25415534d245 | golang.org/ | 0.27.0 | 1 |
| conduction/ | 3423845692c1 | golang.org/ | 0.27.0 | 1 |
| conduction/ | 2744565516e8 | golang.org/ | 0.27.0 | 1 |
| conduction/ | e1d4ad1e22a8 | golang.org/ | 0.27.0 | 1 |
| conduction/ | b6f95c8ead7d | golang.org/ | 0.27.0 | 1 |
| conduction/ | 8f177f9f8a7b | golang.org/ | 0.27.0 | 1 |
| conduction/ | 24f03c57568f | golang.org/ | 0.27.0 | 1 |
| containous/ | 587162516502 | golang.org/ | 0.27.0 | 1 |
| coredns/ | 40384aa1f5ea | golang.org/ | 0.27.0 | 1 |
| coredns/ | 73ca82b4ce82 | golang.org/ | 0.27.0 | 1 |
| coredns/ | 9caabbf6238b | golang.org/ | 0.27.0 | 1 |
| coredns/ | a0ead06651cf | golang.org/ | 0.27.0 | 1 |
| cortezaproject/ | 0bcdcbcd3c63 | golang.org/ | 0.27.0 | 1 |
| cortezaproject/ | 8eb7a26605c9 | golang.org/ | 0.27.0 | 1 |
| cortezaproject/ | cb9f200de5d2 | golang.org/ | 0.27.0 | 1 |
| craftypath/ | 402a0024c732 | golang.org/ | 0.27.0 | 1 |
| crossplane/ | 66666e6963af | golang.org/ | 0.27.0 | 1 |
| crossplane/ | 0112171c45e3 | golang.org/ | 0.27.0 | 1 |
| crossplane/ | 07b8b410dc76 | golang.org/ | 0.27.0 | 1 |
| crowdfox/ | 6fa7e8063d27 | golang.org/ | 0.27.0 | 1 |
| csepulvedab/ | 227a6f2b0ff8 | golang.org/ | 0.27.0 | 1 |