StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,634
of 17,787 indexed, latest versions
Container images
2,031
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,634 of 17,787 indexed charts deploy, on 2,031 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,031
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,634 by stars
ChartLatestAffected imagesRadar Score
wg-access-serverbicarus-labs0.9.91 of 1See more

wg-access-server bicarus-labs 0.9.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bicarus/wg-access-server:v0.8.206cab48e9334
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,748
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

2,318
stackbitpokeVerified publisher0.12.45 of 6See more

stack bitpoke 0.12.4

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

9,897
wordpress-operatorbitpokeVerified publisher0.12.41 of 1See more

wordpress-operator bitpoke 0.12.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitpoke/wordpress-operator:v0.12.421284d1df473
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,123
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

10,171
firehoseblip-firehoseVerified publisher0.0.182 of 11See more

firehose blip-firehose 0.0.18

2 of the 11 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/oauth2@v0.11.0
0.27.0
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/oauth2@v0.11.0
0.27.0

Open the chart page →

13,499
csi-driver-nfsbook-k8sinfra-v24.12.11 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

6,063
grafanabook-k8sinfra-v28.8.21 of 1See more

grafana book-k8sinfra-v2 8.8.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,800
kube-prometheus-stackbook-k8sinfra-v265.5.15 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.2.2-security-01464eac539793
golang.org/x/oauth2@v0.21.0
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

6,035
metallbbook-k8sinfra-v20.13.102 of 3See more

metallb book-k8sinfra-v2 0.13.10

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

3,857
nfs-subdir-external-provisionerbook-k8sinfra-v24.0.181 of 1See more

nfs-subdir-external-provisioner book-k8sinfra-v2 4.0.18

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,745
prometheusbook-k8sinfra-v226.0.16 of 6See more

prometheus book-k8sinfra-v2 26.0.1

6 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/oauth2@v0.22.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

5,304
pyroscopebook-k8sinfra-v21.10.02 of 3See more

pyroscope book-k8sinfra-v2 1.10.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/oauth2@v0.19.0
0.27.0
grafana/pyroscope:1.10.0319bf32ae06b
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

3,244
tempobook-k8sinfra-v21.10.31 of 1See more

tempo book-k8sinfra-v2 1.10.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/tempo:2.5.0f0200a9bff6d
golang.org/x/oauth2@v0.17.0
0.27.0

Open the chart page →

1,859
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

14,446
butane-operatorbutane-operatorVerified publisher0.3.01 of 2See more

butane-operator butane-operator 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,396
butlercibutlerciVerified publisher0.1.01 of 1See more

butlerci butlerci 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0

Open the chart page →

2,374
fluobuttahtoastVerified publisher0.1.01 of 1See more

fluo buttahtoast 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,298
kubermatic-operatorbuttahtoastVerified publisher2.24.51 of 1See more

kubermatic-operator buttahtoast 2.24.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

2,772
kubevirt-managerbuttahtoastVerified publisher0.1.31 of 1See more

kubevirt-manager buttahtoast 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,497
ct-singlecalltelemetry0.8.41 of 7See more

ct-single calltelemetry 0.8.4

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/oauth2@v0.0.0-20181203162652-d668ce993890
0.27.0

Open the chart page →

10,442
stablecalltelemetry0.7.11 of 9See more

stable calltelemetry 0.7.1

1 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/oauth2@v0.0.0-20181203162652-d668ce993890
0.27.0

Open the chart page →

7,702
stable-hacalltelemetry0.11.41 of 7See more

stable-ha calltelemetry 0.11.4

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.2e808e0644ce1
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

4,705
bucket-clonercamptocamp31.0.41 of 1See more

bucket-cloner camptocamp3 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
camptocamp/bucket-cloner:latestacfafc308d88
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0

Open the chart page →

4,518
getconfigcamptocamp30.1.11 of 1See more

getconfig camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,195
prometheus-puppetdb-sdcamptocamp38.0.21 of 2See more

prometheus-puppetdb-sd camptocamp3 8.0.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/prometheus-puppetdb-sd:0.14.0414c0c99fd06
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

6,158
redisoperatorcamptocamp33.0.11 of 1See more

redisoperator camptocamp3 3.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/spotahome/redis-operator:latest8c772955184e
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,193
ssl-exportercamptocamp30.1.01 of 1See more

ssl-exporter camptocamp3 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
golang.org/x/oauth2@v0.0.0-20220630143837-2104d58473e0
0.27.0

Open the chart page →

1,632
terraboardcamptocamp32.4.01 of 1See more

terraboard camptocamp3 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,330
caninecanine0.1.105 of 7See more

canine canine 0.1.10

5 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latesta058034ca006
golang.org/x/oauth2@v0.21.0
0.27.0
quay.io/jetstack/cert-manager-cainjector:v1.15.3e0ce8ae280c8
golang.org/x/oauth2@v0.20.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
golang.org/x/oauth2@v0.20.0
0.27.0
quay.io/jetstack/cert-manager-startupapicheck:v1.15.34cbc1b022a23
golang.org/x/oauth2@v0.20.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

13,363
cert-managercanine1.15.34 of 4See more

cert-manager canine 1.15.3

4 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.15.3e0ce8ae280c8
golang.org/x/oauth2@v0.20.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
golang.org/x/oauth2@v0.20.0
0.27.0
quay.io/jetstack/cert-manager-startupapicheck:v1.15.34cbc1b022a23
golang.org/x/oauth2@v0.20.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

2,880
capsule-argo-addoncapsule-argo-addonVerified publisher0.7.51 of 2See more

capsule-argo-addon capsule-argo-addon 0.7.5

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

2,040
stigatroncarbide-charts0.4.11 of 10See more

stigatron carbide-charts 0.4.1

1 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

4,423
castai-tetragoncastaiVerified publisher0.6.12 of 4See more

castai-tetragon castai 0.6.1

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
quay.io/cilium/tetragon-operator:v0.8.34ab8e6604204
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0

Open the chart page →

4,136
castware-componentscastaiVerified publisher0.4.01 of 1See more

castware-components castai 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

3,451
temporalcastaiVerified publisher0.54.210 of 14See more

temporal castai 0.54.2

10 of the 14 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/oauth2@v0.18.0
0.27.0
temporalio/admin-tools:1.26.237e2e33dbd7b
golang.org/x/oauth2@v0.7.0
0.27.0
temporalio/server:1.26.21e2626efcbc1
golang.org/x/oauth2@v0.23.0
0.27.0
temporalio/ui:2.33.05c586a3c8ec5
golang.org/x/oauth2@v0.22.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/oauth2@v0.19.0
0.27.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/oauth2@v0.21.0
0.27.0
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/oauth2@v0.18.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

16,197
catalyst-agentscatalyst-agents0.1.305 of 18See more

catalyst-agents catalyst-agents 0.1.30

5 of the 18 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
golang.org/x/oauth2@v0.23.0
0.27.0
grafana/loki:3.0.0757b5fadf816
golang.org/x/oauth2@v0.18.0
0.27.0
grafana/loki-canary:3.0.028d7c00588aa
golang.org/x/oauth2@v0.18.0
0.27.0
grafana/tempo:2.5.0f0200a9bff6d
golang.org/x/oauth2@v0.17.0
0.27.0
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

14,865
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

6,389
cert-manager-desec-webhookcert-manager-desec-webhook1.0.11 of 1See more

cert-manager-desec-webhook cert-manager-desec-webhook 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

1,263
cert-manager-webhook-bunnycert-manager-webhook-bunnyVerified publisher1.0.21 of 1See more

cert-manager-webhook-bunny cert-manager-webhook-bunny 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/o0th/cert-manager-webhook-bunny:1.0.2fe7ce555a12d
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

832
cert-manager-webhook-civocert-manager-webhook-civoVerified publisher0.0.0-05b683cb6efdc99135f68af18007954e74f184041 of 1See more

cert-manager-webhook-civo cert-manager-webhook-civo 0.0.0-05b683cb6efdc99135f68af18007954e74f18404

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
okteto/civo-webhook:0.5.357cd51176538
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

1,271
cert-manager-webhook-infoblox-wapicert-manager-webhook-infoblox-wapiVerified publisher1.5.21 of 1See more

cert-manager-webhook-infoblox-wapi cert-manager-webhook-infoblox-wapi 1.5.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

2,345
cert-manager-webhook-namecheapcert-manager-webhook-namecheap0.1.21 of 1See more

cert-manager-webhook-namecheap cert-manager-webhook-namecheap 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,752
cert-manager-webhook-regerycert-manager-webhook-regery1.0.01 of 1See more

cert-manager-webhook-regery cert-manager-webhook-regery 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
darioackermann/cert-manager-webhook-regery:latest0d450bc4acc4
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

882
cert-utils-operatorcert-utils-operator1.3.122 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

7,776
opencvecfi20170.1.21 of 7See more

opencve cfi2017 0.1.2

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

14,964
clechaosnative0.2.73 of 6See more

cle chaosnative 0.2.7

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
chaosnative/cle-auth-server:2.7.072ee352bc333
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
chaosnative/cle-license-module:2.7.062cf6adc355e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
chaosnative/cle-server:2.7.0e7bcff4a20c0
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

16,395
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

8,408
aws-ecr-tokencheveo-charts0.1.01 of 1See more

aws-ecr-token cheveo-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
huzafach/aws-cli-k8:1.0.06e271d43ea48
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,109
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,869

Container images carrying it

2,031 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/oauth2@v0.22.0
0.27.0
1
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
envoyproxy/gateway:v0.5.02a9f99d28567
golang.org/x/oauth2@v0.8.0
0.27.0
1
epamedp/admin-console-operator:2.14.090f9921d8d58
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
epamedp/edp-argocd-operator:0.2.0976a662a5e72
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
epamedp/edp-headlamp:0.25.093417e18bb1a
golang.org/x/oauth2@v0.16.0
0.27.0
1
epamedp/edp-tekton:0.2.4924939850655
golang.org/x/oauth2@v0.1.0
0.27.0
1
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
epamedp/jenkins-operator:2.15.328ef56bc0ca3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
epamedp/perf-operator:2.13.0bd2079b7bfcb
golang.org/x/oauth2@v0.4.0
0.27.0
1
epamedp/reconciler:2.12.0d33e938b6d59
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
epamedp/tekton-custom-task:0.2.067d896676f45
golang.org/x/oauth2@v0.26.0
0.27.0
1
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0
1
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
factly/mande-server:0.34.1384d384310ef
golang.org/x/oauth2@v0.2.0
0.27.0
1
falcosecurity/falcosidekick:2.27.0828ee36cb13a
golang.org/x/oauth2@v0.0.0-20220822191816-0ebed06d0094
0.27.0
1
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
golang.org/x/oauth2@v0.25.0
0.27.0
1
federid/webhook:0.1.0fbfb7c6510a7
golang.org/x/oauth2@v0.23.0
0.27.0
1
fission/fission-bundle:1.14.13fcfd8a0fa5d
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
1
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
1
flanksource/apm-hub:v0.0.471dacc3195bf9
golang.org/x/oauth2@v0.7.0
0.27.0
1
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
fleetdm/fleet:v4.66.012e644b7f40e
golang.org/x/oauth2@v0.22.0
0.27.0
1
flomesh/fsm-ingress-pipy:0.2.11cc39c96711c4
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
flomesh/fsm-manager:0.2.1122f849c70b25
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
golang.org/x/oauth2@v0.4.0
0.27.0
1
flomesh/osm-edge-controller:1.3.9add7a4da4622
golang.org/x/oauth2@v0.4.0
0.27.0
1
flomesh/osm-edge-injector:1.3.947287e3ad324
golang.org/x/oauth2@v0.4.0
0.27.0
1
flomesh/osm-edge-preinstall:1.3.9bd224d55ed0f
golang.org/x/oauth2@v0.4.0
0.27.0
1
fluxcd/helm-controller:v0.9.092b891e495d8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
fluxcd/source-controller:v0.10.031a8c79a6803
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
fluxninja/aperture-operator:2.34.0356d7aa86632
golang.org/x/oauth2@v0.14.0
0.27.0
1
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
golang.org/x/oauth2@v0.5.0
0.27.0
1
foxcpp/maddy:0.7.16ab538e2f28b
golang.org/x/oauth2@v0.16.0
0.27.0
1
foxcpp/maddy:v0.5.28fa2bd8f6830
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0
1
foxcpp/maddy:0.9.2a4b839985b9b
golang.org/x/oauth2@v0.25.0
0.27.0
1
foxcpp/maddy:0.8.2eeb5813fc4d1
golang.org/x/oauth2@v0.25.0
0.27.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
garugaru/presto-exporter:cb666560e9e82d5ae36aef1e663c3d7f51cca9fc5201314c28f3
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
1
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
golang.org/x/oauth2@v0.16.0
0.27.0
1
gitea/gitea:1.22.376f516a1a8c2
golang.org/x/oauth2@v0.21.0
0.27.0
1
gitea/gitea:1.12.485416d6f65fe
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
gitea/gitea:1.21.6ac73e0da341f
golang.org/x/oauth2@v0.13.0
0.27.0
1
gitea/gitea:1.16.8b0bdf102b485
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
gitea/gitea:1.13.0d5ab14cd29af
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.