StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,634
of 17,787 indexed, latest versions
Container images
2,031
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,634 of 17,787 indexed charts deploy, on 2,031 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,031
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,634 by stars
ChartLatestAffected imagesRadar Score
kubedb-provider-azureappscodeVerified publisher2026.7.101 of 1See more

kubedb-provider-azure appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

2,705
kubedb-provider-gcpappscodeVerified publisher2026.7.101 of 2See more

kubedb-provider-gcp appscode 2026.7.10

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

3,033
kubedb-ui-serverappscodeVerified publisher2021.12.211 of 1See more

kubedb-ui-server appscode 2021.12.21

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,047
kubeform-provider-awsappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-aws appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,796
kubeform-provider-azureappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-azure appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,716
kubeform-provider-gcpappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-gcp appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

2,743
kubevirt-infra-csi-driverappscodeVerified publisher0.1.01 of 6See more

kubevirt-infra-csi-driver appscode 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

1,177
kubevirt-tenant-csi-driverappscodeVerified publisher0.1.01 of 4See more

kubevirt-tenant-csi-driver appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,278
license-proxyserver-addon-managerappscodeVerified publisher2024.2.251 of 1See more

license-proxyserver-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.0.8d6c2532ea386
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,384
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

2,404
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

4,043
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

2,568
platform-linksappscodeVerified publisher2026.9.111 of 1See more

platform-links appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

771
service-providerappscodeVerified publisher2026.9.111 of 2See more

service-provider appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

2,224
stash-communityappscodeVerified publisher0.42.03 of 4See more

stash-community appscode 0.42.0

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/oauth2@v0.21.0
0.27.0
ghcr.io/stashed/stash:v0.42.03a98245a7667
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

3,661
statefulsetappscodeVerified publisher0.0.11 of 3See more

statefulset appscode 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,732
vcd-lb-gcappscodeVerified publisher2026.6.251 of 1See more

vcd-lb-gc appscode 2026.6.25

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/vcd-lb-gc:v0.1.0524c4045cd21
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

178
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

1,204
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0

Open the chart page →

5,203
argocdargo-helm-charts1.0.02 of 3See more

argocd argo-helm-charts 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/oauth2@v0.26.0
0.27.0
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

7,338
argonix-apiargonix0.2.31 of 4See more

argonix-api argonix 0.2.3

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

4,819
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

40,411
arma-reforgerarma-reforger0.5.36 of 8See more

arma-reforger arma-reforger 0.5.3

6 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
stakater/reloader:v1.0.15f4b87a8e56d4
golang.org/x/oauth2@v0.4.0
0.27.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/oauth2@v0.3.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

23,407
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,773
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

8,608
assemblylineassemblylineVerified publisher7.4.191 of 12See more

assemblyline assemblyline 7.4.19

1 of the 12 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

12,092
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0

Open the chart page →

18,331
performanceandusagediagnosisassist-iot-pud1.0.04 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

4 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/oauth2@v0.8.0
0.27.0
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

8,556
smartorchestratorassist-iot-smart-orchestrator4.0.01 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

1 of the 14 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

42,460
graph-nodeastria0.2.21 of 3See more

graph-node astria 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ipfs/kubo:v0.17.0803fac58ba15
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

5,394
sequencerastria4.0.01 of 3See more

sequencer astria 4.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0

Open the chart page →

6,239
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,561
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

5,074
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0

Open the chart page →

6,948
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,939
aws-node-termination-handler-2aws0.2.02 of 2See more

aws-node-termination-handler-2 aws 0.2.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/webhook:v2.0.0-beta86b0f7243250
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,952
aws-sigv4-proxy-admission-controlleraws0.1.21 of 1See more

aws-sigv4-proxy-admission-controller aws 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,139
axonops-developer-operatoraxonops-developer-operator0.1.01 of 1See more

axonops-developer-operator axonops-developer-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/axonops/axonops-developer-operator:v0.1.0b3d6600c8ba5
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

749
azure-advanced-backupazure-advanced-backup0.4.11 of 1See more

azure-advanced-backup azure-advanced-backup 0.4.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0

Open the chart page →

4,568
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

5,521
helm-controllerazureorkestra0.1.12 of 2See more

helm-controller azureorkestra 0.1.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
fluxcd/helm-controller:v0.9.092b891e495d8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
fluxcd/source-controller:v0.10.031a8c79a6803
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

7,705
keptn-addonsazureorkestra0.1.02 of 4See more

keptn-addons azureorkestra 0.1.0

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

10,621
prometheusazureorkestra14.8.01 of 6See more

prometheus azureorkestra 14.8.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0

Open the chart page →

9,661
krakendbaboulinet0.1.341 of 1See more

krakend baboulinet 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
devopsfaith/krakend:2.7.09219cda867e2
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

1,191
ragflowbaboulinet0.1.11 of 5See more

ragflow baboulinet 0.1.1

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-12-20T01-00-02Z5702ea361420
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

5,860
prometheus-blackbox-exporterbackbox-exporter7.8.01 of 1See more

prometheus-blackbox-exporter backbox-exporter 7.8.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.23.0ca04aa9d9093
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0

Open the chart page →

1,494
backlokto-operatorbacklokto0.0.11 of 1See more

backlokto-operator backlokto 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
piblokto/backlokto-operator:v0.0.20963cda71e393
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

694
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
conduction/balance-registration-php:devc36094a41369
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

8,408
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,342
trident-operatorberyju-org21.10.01 of 1See more

trident-operator beryju-org 21.10.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
netapp/trident-operator:21.10.049cfe552d9c2
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

2,072

Container images carrying it

2,031 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
golang.org/x/oauth2@v0.0.0-20201203001011-0b49973bad19
0.27.0
1
gitlab/gitlab-runner:alpine-v13.2.1fd7e5dfb9f30
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
gkarthics/container-resource-exporter:latest6799af333e8a
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
goalert/goalert:v0.32.008d57388b0cb
golang.org/x/oauth2@v0.16.0
0.27.0
1
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
golang.org/x/oauth2@v0.25.0
0.27.0
1
goccx/go-file-server:latestf4b3ebea0303
golang.org/x/oauth2@v0.20.0
0.27.0
1
gocrane/craned:v0.5.1a1400909118c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
gocrane/crane-scheduler:0.0.239ba6d11b2079
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
gocrane/crane-scheduler-controller:0.1.23a2d7e60576f9
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
goharbor/chartmuseum-photon:v2.5.36ab3ca28e9e5
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
goharbor/harbor-core:v2.9.06412d679fdc3
golang.org/x/oauth2@v0.5.0
0.27.0
1
goharbor/harbor-core:v2.5.386bf3031f4a7
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
goharbor/harbor-core:v2.11.1c017dd84ee96
golang.org/x/oauth2@v0.19.0
0.27.0
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/oauth2@v0.5.0
0.27.0
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/oauth2@v0.7.0
0.27.0
1
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0
1
gomods/athens:v0.11.0efb811df7844
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
grafana/agent:v0.44.23364714a2f64
golang.org/x/oauth2@v0.21.0
0.27.0
1
grafana/agent:v0.20.0825c09373d27
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/oauth2@v0.16.0
0.27.0
1
grafana/agent-operator:v0.34.1045c9125634c
golang.org/x/oauth2@v0.7.0
0.27.0
1
grafana/alloy:v1.5.101a63f4e032c
golang.org/x/oauth2@v0.23.0
0.27.0
1
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/oauth2@v0.22.0
0.27.0
1
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/oauth2@v0.19.0
0.27.0
1
grafana/beyla:1.3.336d07f8d276e
golang.org/x/oauth2@v0.16.0
0.27.0
1
grafana/grafana:6.6.0052147d7e0ec
golang.org/x/oauth2@v0.0.0-20190319182350-c85d3e98c914
0.27.0
1
grafana/grafana:10.1.50679e877ba20
golang.org/x/oauth2@v0.8.0
0.27.0
1
grafana/grafana:7.5.609bb407e26ab
golang.org/x/oauth2@v0.0.0-20210113205817-d3ed898aa8a3
0.27.0
1
grafana/grafana:7.3.315b977f5207d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
grafana/grafana:9.4.71a359d92f40e
golang.org/x/oauth2@v0.3.0
0.27.0
1
grafana/grafana:10.1.11b9ca4bbc4a2
golang.org/x/oauth2@v0.8.0
0.27.0
1
grafana/grafana:9.5.239c849cebccc
golang.org/x/oauth2@v0.6.0
0.27.0
1
grafana/grafana:11.2.2-security-01464eac539793
golang.org/x/oauth2@v0.21.0
0.27.0
1
grafana/grafana:11.5.15781759b3d27
golang.org/x/oauth2@v0.25.0
0.27.0
1
grafana/grafana:8.0.3696823fbc561
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0
1
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/oauth2@v0.15.0
0.27.0
1
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
grafana/grafana:7.2.1733842cca5bd
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/oauth2@v0.3.0
0.27.0
1
grafana/grafana:10.3.38640e5038e83
golang.org/x/oauth2@v0.15.0
0.27.0
1
grafana/grafana:11.5.28b37a2f028f1
golang.org/x/oauth2@v0.25.0
0.27.0
1
grafana/grafana:9.1.19746858c20e6
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
1
grafana/grafana:9.0.1a738d0744784
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
1
grafana/grafana:11.1.3b23b588cf7cb
golang.org/x/oauth2@v0.20.0
0.27.0
1
grafana/grafana:6.5.1befcd84da2c1
golang.org/x/oauth2@v0.0.0-20190319182350-c85d3e98c914
0.27.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.