StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,634
of 17,787 indexed, latest versions
Container images
2,031
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,634 of 17,787 indexed charts deploy, on 2,031 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,031
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,634 by stars
ChartLatestAffected imagesRadar Score
gateway-helmappscodeVerified publisher0.0.0-latest1 of 2See more

gateway-helm appscode 0.0.0-latest

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,057
scannerappscodeVerified publisher2026.1.151 of 3See more

scanner appscode 2026.1.15

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

5,301
smtprelayappscodeVerified publisher2026.9.111 of 1See more

smtprelay appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

840
stash-enterpriseappscodeVerified publisher0.42.03 of 4See more

stash-enterprise appscode 0.42.0

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/oauth2@v0.21.0
0.27.0
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

3,620
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

5,231
kedaarieotechVerified publisher0.1.02 of 3See more

keda arieotech 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.16.002348a19aeae
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,276
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0

Open the chart page →

2,819
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

10,731
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

4,298
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/oauth2@v0.0.0-20201203001011-0b49973bad19
0.27.0

Open the chart page →

3,391
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,814
chirpstackbeeinventor0.1.102 of 5See more

chirpstack beeinventor 0.1.10

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

7,807
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

1,595
helm-dashboardbeluga-cloudVerified publisher2.4.01 of 1See more

helm-dashboard beluga-cloud 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

2,900
boundaryboundary-chart0.3.121 of 1See more

boundary boundary-chart 0.3.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,623
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,830
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

2,042
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/oauth2@v0.0.0-20181003184128-c57b0facaced
0.27.0

Open the chart page →

2,663
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,483
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,483
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

906
capsulecapsuleOfficialVerified publisher0.14.51 of 2See more

capsule capsule 0.14.5

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,231
capsule-proxycapsule-proxyOfficialVerified publisher0.14.11 of 2See more

capsule-proxy capsule-proxy 0.14.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,224
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,509
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,799
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
golang.org/x/oauth2@v0.20.0
0.27.0
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

12,561
cert-manager-webhook-arvancloudcert-manager-webhook-arvancloudVerified publisher0.1.11 of 1See more

cert-manager-webhook-arvancloud cert-manager-webhook-arvancloud 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,067
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

1,024
cert-vaultcert-vaultOfficialVerified publisher2.12.01 of 7See more

cert-vault cert-vault 2.12.0

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

15,995
chatclichatcliVerified publisher1.204.01 of 2See more

chatcli chatcli 1.204.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,028
access-managerckotzbauerVerified publisher0.14.31 of 1See more

access-manager ckotzbauer 0.14.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/access-managerdigest-pinneddd584fcda0ff
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

643
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,268
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220201 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

1 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,256
cnpg-sandboxcloudnative-pgVerified publisher0.6.13 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

7,583
cloudttycloudtty0.8.91 of 2See more

cloudtty cloudtty 0.8.9

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell-operator:v0.8.9e43ad91f0684
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

3,958
cluster-setupcluster-setup1.5.01 of 8See more

cluster-setup cluster-setup 1.5.0

1 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

10,076
istio-allcode4devsVerified publisher1.2.04 of 6See more

istio-all code4devs 1.2.0

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/oauth2@v0.23.0
0.27.0
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
golang.org/x/oauth2@v0.19.0
0.27.0
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

4,784
istio-control-planecode4devsVerified publisher1.0.02 of 3See more

istio-control-plane code4devs 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/oauth2@v0.23.0
0.27.0
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,360
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,303
cosmo-controller-managercosmoVerified publisher0.9.01 of 2See more

cosmo-controller-manager cosmo 0.9.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-controller-manager:v0.9.08c7fa5552028
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,927
cosmo-dashboardcosmoVerified publisher0.9.11 of 1See more

cosmo-dashboard cosmo 0.9.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-dashboard:v0.9.16a1c4a81a924
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,939
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0

Open the chart page →

6,473
revadcs3orgOfficialVerified publisher1.6.11 of 1See more

revad cs3org 1.6.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

1,704
cubefscubefs3.2.05 of 10See more

cubefs cubefs 3.2.0

5 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0

Open the chart page →

15,891
CubeUniversecubeuniverseVerified publisher0.1.01 of 1See more

CubeUniverse cubeuniverse 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,837
cyphernetes-operatorcyphernetes-operatorVerified publisher0.1.01 of 1See more

cyphernetes-operator cyphernetes-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

498
aibrixdanchevVerified publisher0.7.02 of 5See more

aibrix danchev 0.7.0

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aibrix/controller-manager:v0.7.076aabbbfda79
golang.org/x/oauth2@v0.21.0
0.27.0
aibrix/gateway-plugins:v0.7.05b93ea4c753a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

5,298
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,759
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,570
dbrepodbrepo1.13.34 of 25See more

dbrepo dbrepo 1.13.3

4 of the 25 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
golang.org/x/oauth2@v0.23.0
0.27.0
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
golang.org/x/oauth2@v0.12.0
0.27.0
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
golang.org/x/oauth2@v0.8.0
0.27.0
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

50,281

Container images carrying it

2,031 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
grafana/grafana:8.3.4cf81d2c753c8
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
grafana/grafana:7.4.5d322192ed2fa
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
grafana/grafana:8.5.3ecc1b80b8ca2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
grafana/grafana:10.4.0f9811e4e687f
golang.org/x/oauth2@v0.16.0
0.27.0
1
grafana/grafana:11.3.1fa801ab6e1ae
golang.org/x/oauth2@v0.23.0
0.27.0
1
grafana/kubernetes-diff-logger:0.0.598f6d1cd1e25
golang.org/x/oauth2@v0.0.0-20210615190721-d04028783cf1
0.27.0
1
grafana/logcli:main-c90366d-amd643d85bb66e39b
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0
1
grafana/loki:2.9.1035b02acc6765
golang.org/x/oauth2@v0.10.0
0.27.0
1
grafana/loki:2.9.26074e01dbe03
golang.org/x/oauth2@v0.10.0
0.27.0
1
grafana/loki:2.9.66ca6e2cd3b6f
golang.org/x/oauth2@v0.10.0
0.27.0
1
grafana/loki:3.0.0757b5fadf816
golang.org/x/oauth2@v0.18.0
0.27.0
1
grafana/loki:2.0.077e138f81a8e
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
grafana/loki:3.2.0882e30c20683
golang.org/x/oauth2@v0.22.0
0.27.0
1
grafana/loki:3.3.28af2de1abbdd
golang.org/x/oauth2@v0.23.0
0.27.0
1
grafana/loki:2.8.2b1da1d23037e
golang.org/x/oauth2@v0.4.0
0.27.0
1
grafana/loki:2.4.2b3af8ead67d7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
grafana/loki-canary:3.0.028d7c00588aa
golang.org/x/oauth2@v0.18.0
0.27.0
1
grafana/loki-canary:3.1.039baf6d67f85
golang.org/x/oauth2@v0.18.0
0.27.0
1
grafana/loki-canary:2.9.24249db29b992
golang.org/x/oauth2@v0.10.0
0.27.0
1
grafana/loki-canary:3.2.049e03f80d361
golang.org/x/oauth2@v0.22.0
0.27.0
1
grafana/loki-canary:2.9.6549a40203e97
golang.org/x/oauth2@v0.10.0
0.27.0
1
grafana/loki-canary:2.6.1ab2a2569307b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
grafana/mimir:r292-5f018727476e456c738
golang.org/x/oauth2@v0.19.0
0.27.0
1
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
grafana/mimir:2.15.085f55510e0d3
golang.org/x/oauth2@v0.24.0
0.27.0
1
grafana/phlare:0.5.1330f990cdad9
golang.org/x/oauth2@v0.3.0
0.27.0
1
grafana/promtail:2.6.1072527b12cdf
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
grafana/promtail:2.0.05fd12edcc694
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
grafana/promtail:2.9.1063a2e57a5b14
golang.org/x/oauth2@v0.10.0
0.27.0
1
grafana/promtail:2.7.0c16c710f7333
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
1
grafana/promtail:3.0.0d3de3da9431c
golang.org/x/oauth2@v0.18.0
0.27.0
1
grafana/pyroscope:1.10.0319bf32ae06b
golang.org/x/oauth2@v0.21.0
0.27.0
1
grafana/rollout-operator:v0.14.03409edfb45c7
golang.org/x/oauth2@v0.17.0
0.27.0
1
grafana/tempo:2.6.0f55a8a1937ff
golang.org/x/oauth2@v0.21.0
0.27.0
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
golang.org/x/oauth2@v0.0.0-20180821212333-d2e6202438be
0.27.0
1
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/oauth2@v0.19.0
0.27.0
1
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
grpl/grapple-cli:0.2.127c00aafee6629
golang.org/x/oauth2@v0.21.0
0.27.0
1
gutmensch/podnat-controller:0.5.2566979793fc4
golang.org/x/oauth2@v0.3.0
0.27.0
1
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
golang.org/x/oauth2@v0.17.0
0.27.0
1
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/oauth2@v0.13.0
0.27.0
1
hashicorp/boundary:0.8.1fb70bd9210ff
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
1
hashicorp/consul:1.17.0712fe02d2f84
golang.org/x/oauth2@v0.7.0
0.27.0
1
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/oauth2@v0.6.0
0.27.0
1
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
hashicorp/terraform:1.44dcb45513699
golang.org/x/oauth2@v0.4.0
0.27.0
1
hashicorp/terraform:1.9.7b77efab1a448
golang.org/x/oauth2@v0.18.0
0.27.0
1
hashicorp/terraform-cloud-operator:2.5.0c2f78a575a8a
golang.org/x/oauth2@v0.12.0
0.27.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.