StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,634
of 17,790 indexed, latest versions
Container images
2,030
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,634 of 17,790 indexed charts deploy, on 2,030 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,030
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,634 by stars
ChartLatestAffected imagesRadar Score
ingress-nginxgpg-dev4.9.02 of 2See more

ingress-nginx gpg-dev 4.9.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/oauth2@v0.12.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

2,316
kubernetes-dashboardgpg-dev7.5.04 of 5See more

kubernetes-dashboard gpg-dev 7.5.0

4 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubernetesui/dashboard-api:1.7.060595892c2cf
golang.org/x/oauth2@v0.16.0
0.27.0
kubernetesui/dashboard-auth:1.1.307135c09e9ff
golang.org/x/oauth2@v0.16.0
0.27.0
kubernetesui/dashboard-metrics-scraper:1.1.17747d363c9fe
golang.org/x/oauth2@v0.12.0
0.27.0
kubernetesui/dashboard-web:1.4.04445b31a2c25
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

6,075
metrics-servergpg-dev3.12.11 of 1See more

metrics-server gpg-dev 3.12.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,071
opentelemetry-demogpg-dev0.33.84 of 27See more

opentelemetry-demo gpg-dev 0.33.8

4 of the 27 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.3.1fa801ab6e1ae
golang.org/x/oauth2@v0.23.0
0.27.0
otel/opentelemetry-collector-contrib:0.114.037fa87091cfa
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/open-feature/flagd:v0.11.1a7ea52f87446
golang.org/x/oauth2@v0.21.0
0.27.0
quay.io/prometheus/prometheus:v3.0.03b9b2a15d376
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

47,117
prometheus-operator-admission-webhookgpg-dev0.18.12 of 2See more

prometheus-operator-admission-webhook gpg-dev 0.18.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/admission-webhook:v0.79.2d4c97a1b2d67
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,685
grafana-cloud-onboardinggrafana0.4.71 of 5See more

grafana-cloud-onboarding grafana 0.4.7

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

4,657
grafana-samplinggrafana1.1.71 of 2See more

grafana-sampling grafana 1.1.7

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

3,357
mimir-openshift-experimentalgrafana2.1.02 of 4See more

mimir-openshift-experimental grafana 2.1.0

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0

Open the chart page →

17,759
pyroscope-monitoringgrafana0.1.11 of 6See more

pyroscope-monitoring grafana 0.1.1

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

8,226
prometheusgrafana-uxadax26.0.16 of 6See more

prometheus grafana-uxadax 26.0.1

6 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/oauth2@v0.22.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

5,304
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,510
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

7,935
fasttrackmlgresearch0.1.01 of 1See more

fasttrackml gresearch 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

1,391
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.18.16a41efe02a041
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

14,312
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

2,589
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,175
docker-authhalkeye0.1.11 of 1See more

docker-auth halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,374
cert-manager-webhook-arvanhbahadorzadeh0.1.11 of 1See more

cert-manager-webhook-arvan hbahadorzadeh 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,022
kubernetes-event-exporterhbahadorzadeh0.1.01 of 1See more

kubernetes-event-exporter hbahadorzadeh 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,630
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
supabase/gotrue:v2.91.07174d551d720
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

23,472
helm-airportshelm-airports0.1.01 of 7See more

helm-airports helm-airports 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

12,696
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

4,547
helm-airportshelm-airports-dan0.1.01 of 7See more

helm-airports helm-airports-dan 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

5,573
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

4,547
logging-stackhelm-charts-alexis-carbillet0.1.05 of 9See more

logging-stack helm-charts-alexis-carbillet 0.1.0

5 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
grafana/grafana:11.1.0079600c9517b
golang.org/x/oauth2@v0.20.0
0.27.0
grafana/loki:2.6.11ee60f980950
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
grafana/loki:2.8.2b1da1d23037e
golang.org/x/oauth2@v0.4.0
0.27.0
grafana/loki-canary:2.6.1ab2a2569307b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

12,650
monitoring-stackhelm-charts-alexis-carbillet0.1.07 of 11See more

monitoring-stack helm-charts-alexis-carbillet 0.1.0

7 of the 11 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/oauth2@v0.23.0
0.27.0
prom/prometheus:v2.48.1a67e5e402ff5
golang.org/x/oauth2@v0.13.0
0.27.0
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/oauth2@v0.8.0
0.27.0
quay.io/prometheus/node-exporter:v1.7.04cb2b9019f17
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/oauth2@v0.8.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

9,461
aws-ebs-csi-driverhelm-charts-nr2.17.44 of 6See more

aws-ebs-csi-driver helm-charts-nr 2.17.4

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/oauth2@v0.1.0
0.27.0
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/oauth2@v0.2.0
0.27.0
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

6,485
cortex-gatewayhelm-charts-nr0.1.91 of 1See more

cortex-gateway helm-charts-nr 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0

Open the chart page →

2,234
dregsyhelm-charts-nr0.1.51 of 1See more

dregsy helm-charts-nr 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/oauth2@v0.0.0-20201109201403-9fd604954f58
0.27.0

Open the chart page →

2,969
k8s-cloudwatch-adapterhelm-charts-nr0.2.21 of 1See more

k8s-cloudwatch-adapter helm-charts-nr 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,468
k8s-event-loggerhelm-charts-nr1.1.91 of 1See more

k8s-event-logger helm-charts-nr 1.1.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
maxrocketinternet/k8s-event-logger:2.111224534789d
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0

Open the chart page →

864
kube-benchhelm-charts-nr0.1.171 of 1See more

kube-bench helm-charts-nr 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,623
labelsmanager-controllerhelm-charts-nr1.0.41 of 1See more

labelsmanager-controller helm-charts-nr 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,305
node-local-dnshelm-charts-nr2.1.41 of 1See more

node-local-dns helm-charts-nr 2.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

2,128
node-problem-detectorhelm-charts-nr2.3.171 of 1See more

node-problem-detector helm-charts-nr 2.3.17

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

2,349
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/oauth2@v0.0.0-20181106182150-f42d05182288
0.27.0

Open the chart page →

7,987
answerhelmforgeVerified publisher1.5.21 of 1See more

answer helmforge 1.5.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apache/answer:2.0.2a0d71b0e30a5
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

557
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

25,099
printserverhmediadeVerified publisher1.0.22 of 4See more

printserver hmediade 1.0.2

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/oauth2@v0.12.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

10,918
imageproxyhmphuVerified publisher0.1.11 of 1See more

imageproxy hmphu 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0

Open the chart page →

2,140
cert-managerhomeenterpriseinc1.10.13 of 3See more

cert-manager homeenterpriseinc 1.10.1

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.10.164121721c665
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0

Open the chart page →

4,720
hammerspace-csihscsi1.2.83 of 6See more

hammerspace-csi hscsi 1.2.8

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/oauth2@v0.25.0
0.27.0
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

4,440
cac-systemhuangchengwu-helm-chart0.1.07 of 9See more

cac-system huangchengwu-helm-chart 0.1.0

7 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
golang.org/x/oauth2@v0.6.0
0.27.0
quay.io/jetstack/cert-manager-cainjector:v1.12.0e0a5b06b231c
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.12.0ec4306b243d9
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

11,190
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

16,482
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

20,727
tdenginehuangchengwu-helm-chart3.0.21 of 1See more

tdengine huangchengwu-helm-chart 3.0.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tdengine/tdengine:3.0.2.24140a4021ddb
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0

Open the chart page →

3,753
stoloniamalryz0.10.01 of 2See more

stolon iamalryz 0.10.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,045
monitoring-stackict-platformVerified publisher0.4.02 of 13See more

monitoring-stack ict-platform 0.4.0

2 of the 13 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
golang.org/x/oauth2@v0.23.0
0.27.0
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

9,597
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

9,032
ikigaiikigai-chartVerified publisher0.0.93 of 58See more

ikigai ikigai-chart 0.0.9

3 of the 58 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kuberay/operator:v1.0.04e6ac8a3a2c4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
rabbitmqoperator/cluster-operator:2.6.08651dd3cec51
golang.org/x/oauth2@v0.8.0
0.27.0
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

37,844

Container images carrying it

2,030 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
grafana/grafana:8.3.4cf81d2c753c8
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
grafana/grafana:7.4.5d322192ed2fa
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
grafana/grafana:8.5.3ecc1b80b8ca2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
grafana/grafana:10.4.0f9811e4e687f
golang.org/x/oauth2@v0.16.0
0.27.0
1
grafana/grafana:11.3.1fa801ab6e1ae
golang.org/x/oauth2@v0.23.0
0.27.0
1
grafana/kubernetes-diff-logger:0.0.598f6d1cd1e25
golang.org/x/oauth2@v0.0.0-20210615190721-d04028783cf1
0.27.0
1
grafana/logcli:main-c90366d-amd643d85bb66e39b
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0
1
grafana/loki:2.9.1035b02acc6765
golang.org/x/oauth2@v0.10.0
0.27.0
1
grafana/loki:2.9.26074e01dbe03
golang.org/x/oauth2@v0.10.0
0.27.0
1
grafana/loki:2.9.66ca6e2cd3b6f
golang.org/x/oauth2@v0.10.0
0.27.0
1
grafana/loki:3.0.0757b5fadf816
golang.org/x/oauth2@v0.18.0
0.27.0
1
grafana/loki:2.0.077e138f81a8e
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
grafana/loki:3.2.0882e30c20683
golang.org/x/oauth2@v0.22.0
0.27.0
1
grafana/loki:3.3.28af2de1abbdd
golang.org/x/oauth2@v0.23.0
0.27.0
1
grafana/loki:2.8.2b1da1d23037e
golang.org/x/oauth2@v0.4.0
0.27.0
1
grafana/loki:2.4.2b3af8ead67d7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
grafana/loki-canary:3.0.028d7c00588aa
golang.org/x/oauth2@v0.18.0
0.27.0
1
grafana/loki-canary:3.1.039baf6d67f85
golang.org/x/oauth2@v0.18.0
0.27.0
1
grafana/loki-canary:2.9.24249db29b992
golang.org/x/oauth2@v0.10.0
0.27.0
1
grafana/loki-canary:3.2.049e03f80d361
golang.org/x/oauth2@v0.22.0
0.27.0
1
grafana/loki-canary:2.9.6549a40203e97
golang.org/x/oauth2@v0.10.0
0.27.0
1
grafana/loki-canary:2.6.1ab2a2569307b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
grafana/mimir:r292-5f018727476e456c738
golang.org/x/oauth2@v0.19.0
0.27.0
1
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
grafana/mimir:2.15.085f55510e0d3
golang.org/x/oauth2@v0.24.0
0.27.0
1
grafana/phlare:0.5.1330f990cdad9
golang.org/x/oauth2@v0.3.0
0.27.0
1
grafana/promtail:2.6.1072527b12cdf
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
grafana/promtail:2.0.05fd12edcc694
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
grafana/promtail:2.9.1063a2e57a5b14
golang.org/x/oauth2@v0.10.0
0.27.0
1
grafana/promtail:2.7.0c16c710f7333
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
1
grafana/promtail:3.0.0d3de3da9431c
golang.org/x/oauth2@v0.18.0
0.27.0
1
grafana/pyroscope:1.10.0319bf32ae06b
golang.org/x/oauth2@v0.21.0
0.27.0
1
grafana/rollout-operator:v0.14.03409edfb45c7
golang.org/x/oauth2@v0.17.0
0.27.0
1
grafana/tempo:2.6.0f55a8a1937ff
golang.org/x/oauth2@v0.21.0
0.27.0
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
golang.org/x/oauth2@v0.0.0-20180821212333-d2e6202438be
0.27.0
1
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/oauth2@v0.19.0
0.27.0
1
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
grpl/grapple-cli:0.2.127c00aafee6629
golang.org/x/oauth2@v0.21.0
0.27.0
1
gutmensch/podnat-controller:0.5.2566979793fc4
golang.org/x/oauth2@v0.3.0
0.27.0
1
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
golang.org/x/oauth2@v0.17.0
0.27.0
1
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/oauth2@v0.13.0
0.27.0
1
hashicorp/boundary:0.8.1fb70bd9210ff
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
1
hashicorp/consul:1.17.0712fe02d2f84
golang.org/x/oauth2@v0.7.0
0.27.0
1
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/oauth2@v0.6.0
0.27.0
1
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
hashicorp/terraform:1.44dcb45513699
golang.org/x/oauth2@v0.4.0
0.27.0
1
hashicorp/terraform:1.9.7b77efab1a448
golang.org/x/oauth2@v0.18.0
0.27.0
1
hashicorp/terraform-cloud-operator:2.5.0c2f78a575a8a
golang.org/x/oauth2@v0.12.0
0.27.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.