StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,632
of 17,792 indexed, latest versions
Container images
2,029
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,632 of 17,792 indexed charts deploy, on 2,029 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,029
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,632 by stars
ChartLatestAffected imagesRadar Score
k8s-ondemand-proxyk8s-ondemand-proxy0.0.61 of 1See more

k8s-ondemand-proxy k8s-ondemand-proxy 0.0.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/k8s-ondemand-proxy:0.0.2078b25d48cf7
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

815
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.22.600ac10bcb759
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

14,872
k8s-pausek8s-pause0.1.41 of 1See more

k8s-pause k8s-pause 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,846
k8s-ssh-bastionk8s-ssh-bastion0.5.41 of 1See more

k8s-ssh-bastion k8s-ssh-bastion 0.5.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,327
k8s-validating-webhookk8s-validating-webhook0.4.01 of 2See more

k8s-validating-webhook k8s-validating-webhook 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

2,010
kube-admission-controller-starterk8s-validating-webhook0.2.01 of 2See more

kube-admission-controller-starter k8s-validating-webhook 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

2,167
k8svault-controllerk8svault-controller0.1.21 of 1See more

k8svault-controller k8svault-controller 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,885
kagentkagent0.10.11 of 6See more

kagent kagent 0.10.1

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kagent-dev/kmcp/controller:0.3.086ab878da25a
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,942
kom-operatorkaisoVerified publisher1.3.01 of 2See more

kom-operator kaiso 1.3.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kaiso/kom-operator:v2.2.0e0e22b928bdd
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

710
gpu-provisionerkaitoVerified publisher0.2.01 of 1See more

gpu-provisioner kaito 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mcr.microsoft.com/aks/kaito/gpu-provisioner:0.2.01204a7e948e9
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

1,045
workspacekaitoVerified publisher0.12.02 of 7See more

workspace kaito 0.12.0

2 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v5.2.0afdfa3da79df
golang.org/x/oauth2@v0.25.0
0.27.0
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v1.13.2fa8eba9843ff
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

2,410
keeper-injectorkeeper-injectorVerified publisher0.10.01 of 2See more

keeper-injector keeper-injector 0.10.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

758
keeper-injectorkeeper-securityVerified publisher0.11.31 of 2See more

keeper-injector keeper-security 0.11.3

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

505
keycloak-operator-legacykeycloak-operator-legacy1.0.01 of 1See more

keycloak-operator-legacy keycloak-operator-legacy 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

5,066
helm-mongodb-operatorkeyporttech0.1.01 of 1See more

helm-mongodb-operator keyporttech 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

8,819
dex-k8s-authenticatorkfirfer0.0.31 of 1See more

dex-k8s-authenticator kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,791
keelkfirfer1.0.51 of 1See more

keel kfirfer 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
keelhq/keel:0.19.202ac4ea616c4
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

2,083
kubernetes-replicatorkfirfer2.9.11 of 1See more

kubernetes-replicator kfirfer 2.9.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.9.1baf5f784398b
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

864
mysqldumpkfirfer2.8.01 of 1See more

mysqldump kfirfer 2.8.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,514
prometheus-elasticsearch-exporterkfirfer6.5.11 of 1See more

prometheus-elasticsearch-exporter kfirfer 6.5.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/elasticsearch-exporter:v1.8.0073dd360de2c
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

778
kiaekiae0.1.66 of 9See more

kiae kiae 0.1.6

6 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
grafana/promtail:2.6.1072527b12cdf
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
istio/pilot:1.15.2db08d6963975
golang.org/x/oauth2@v0.0.0-20220622183110-fd043fe589d2
0.27.0
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
ghcr.io/kiaedev/kiae:latestebd03028ff6a
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0

Open the chart page →

19,257
process-exporterkir4hVerified publisher1.0.11 of 1See more

process-exporter kir4h 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ncabatoff/process-exporterdigest-pinned6f0549dc24e9
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

741
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

12,206
kloudlite-platformkloudlite1.1.51 of 3See more

kloudlite-platform kloudlite 1.1.5

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,970
knative-servingknative-servingVerified publisher1.18.37 of 7See more

knative-serving knative-serving 1.18.3

7 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinned0d5f740b4224
golang.org/x/oauth2@v0.26.0
0.27.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned697668be7893
golang.org/x/oauth2@v0.26.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned031408ec516f
golang.org/x/oauth2@v0.26.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned3502bb5aa60f
golang.org/x/oauth2@v0.26.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpadigest-pinned7405faeb7636
golang.org/x/oauth2@v0.26.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
golang.org/x/oauth2@v0.26.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned50831d9aaa69
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

3,777
kollektorkollektorVerified publisher1.0.51 of 1See more

kollektor kollektor 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
pannoi/kollektor:1.0.59559617788fc
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

717
ingress-nginxkomailo-helm-charts1.0.02 of 2See more

ingress-nginx komailo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
golang.org/x/oauth2@v0.23.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,548
komiserkomiser-eks3.1.101 of 1See more

komiser komiser-eks 3.1.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tailwarden/komiser:3.1.103f68c8ae7993
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,272
simple-oauth2-proxykostiantyn-matsebora-helm-chartsVerified publisher0.3.71 of 1See more

simple-oauth2-proxy kostiantyn-matsebora-helm-charts 0.3.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.7.09ed7eaf72050
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

927
kovi-tile38kovi-charts0.1.11 of 1See more

kovi-tile38 kovi-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tile38/tile38:1.33.4afb7e82f9485
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,208
cadvisorkrakazyabraVerified publisher1.0.11 of 1See more

cadvisor krakazyabra 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0

Open the chart page →

3,185
installerkrateo2.7.11 of 2See more

installer krateo 2.7.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,252
installer-pre-upgradekrateo2.7.11 of 1See more

installer-pre-upgrade krateo 2.7.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

2,542
kubeflowkromanow94-kubeflow0.5.114 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

14 of the 30 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeflow/training-operator:v1-04f9f13dabb76dbda29
golang.org/x/oauth2@v0.12.0
0.27.0
kubeflowkatib/katib-controller:v0.17.072f14e03b9e1
golang.org/x/oauth2@v0.12.0
0.27.0
kubeflowkatib/katib-ui:v0.17.07a41c508deb1
golang.org/x/oauth2@v0.12.0
0.27.0
kubeflownotebookswg/kfam:v1.9.22060a2ede788
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
kubeflownotebookswg/notebook-controller:v1.9.20f14bd28fdd5
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
kubeflownotebookswg/poddefaults-webhook:v1.9.2bde88d98ad74
golang.org/x/oauth2@v0.8.0
0.27.0
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
kubeflownotebookswg/pvcviewer-controller:v1.9.29815e9b1728f
golang.org/x/oauth2@v0.19.0
0.27.0
kubeflownotebookswg/tensorboard-controller:v1.9.26536a9f61193
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
golang.org/x/oauth2@v0.16.0
0.27.0
gcr.io/ml-pipeline/cache-server:2.3.0293941ee4f65
golang.org/x/oauth2@v0.16.0
0.27.0
gcr.io/ml-pipeline/persistenceagent:2.3.0109ac1b38c41
golang.org/x/oauth2@v0.16.0
0.27.0
gcr.io/ml-pipeline/scheduledworkflow:2.3.0f7e67e0bc071
golang.org/x/oauth2@v0.16.0
0.27.0
gcr.io/ml-pipeline/viewer-crd-controller:2.3.08cf8213d69e4
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

70,968
kron-aapm-sidecarkron-aapm-sidecar1.1.01 of 1See more

kron-aapm-sidecar kron-aapm-sidecar 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,111
casdoorkrzwiatrzyk1.0.01 of 1See more

casdoor krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
casbin/casdoor:v1.224.066f836ef778b
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

3,649
nocodbkrzwiatrzyk0.0.11 of 1See more

nocodb krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
nocodb/nocodb:0.100.2b0b91ec2a2dd
golang.org/x/oauth2@v0.0.0-20220808172628-8227340efae7
0.27.0

Open the chart page →

2,320
pipecdkrzwiatrzyk0.39.01 of 3See more

pipecd krzwiatrzyk 0.39.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

3,819
ksoc-pluginsksocOfficialVerified publisher1.9.105 of 5See more

ksoc-plugins ksoc 1.9.10

5 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/n8h5y2v5/rad-security/rad-bootstrapper:v1.1.115ca2d500d374
golang.org/x/oauth2@v0.21.0
0.27.0
public.ecr.aws/n8h5y2v5/rad-security/rad-guard:v1.1.17a94d2d4aae85
golang.org/x/oauth2@v0.21.0
0.27.0
public.ecr.aws/n8h5y2v5/rad-security/rad-sbom:v1.1.34e97e0e7a2088
golang.org/x/oauth2@v0.22.0
0.27.0
public.ecr.aws/n8h5y2v5/rad-security/rad-sync:v1.1.1514f3dfbc0225
golang.org/x/oauth2@v0.21.0
0.27.0
public.ecr.aws/n8h5y2v5/rad-security/rad-watch:v1.1.25b9a7d6bc2a0c
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

3,207
bc-depositorykubebb0.0.31 of 1See more

bc-depository kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

1,947
bc-explorerkubebb0.0.31 of 1See more

bc-explorer kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

1,947
chartmuseumkubebb3.10.21 of 1See more

chartmuseum kubebb 3.10.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

2,276
cluster-componentkubebb0.2.24 of 4See more

cluster-component kubebb 0.2.2

4 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
kubebb/cert-manager-controller:v1.8.020509de4b399
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

8,174
fabric-operatorkubebb0.1.01 of 1See more

fabric-operator kubebb 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

3,995
ingress-nginxkubebb4.7.02 of 2See more

ingress-nginx kubebb 4.7.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
golang.org/x/oauth2@v0.7.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,099
kubebbkubebb0.0.11 of 1See more

kubebb kubebb 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubebb/core:lateste366c34a9b8d
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,758
kubebb-corekubebb0.1.271 of 1See more

kubebb-core kubebb 0.1.27

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubebb/core:v0.1.62b9e7f451d6b
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

1,947
miniokubebb5.0.101 of 2See more

minio kubebb 5.0.10

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

7,471
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubebb/mesh-operator:v5.7.0163ebbfc7a82
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

6,502
tekton-operatorkubebb0.64.02 of 2See more

tekton-operator kubebb 0.64.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
golang.org/x/oauth2@v0.2.0
0.27.0
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
golang.org/x/oauth2@v0.2.0
0.27.0

Open the chart page →

2,420

Container images carrying it

2,029 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
iomesh/node-disk-operator:1.8.0f6c76380db34
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
iomesh/operator:v1.1.060081c9b2f52
golang.org/x/oauth2@v0.13.0
0.27.0
1
iomesh/operator:v1.2.0ba4dd6be7e59
golang.org/x/oauth2@v0.13.0
0.27.0
1
iomesh/post-delete-hook:v1.2.0e3b92f838f4b
golang.org/x/oauth2@v0.13.0
0.27.0
1
iomesh/post-delete-hook:v1.1.0eea5651f3270
golang.org/x/oauth2@v0.13.0
0.27.0
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
ipfs/go-ipfs:v0.13.117259397f587
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ipfs/kubo:v0.17.0803fac58ba15
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ipfs/kubo:v0.24.0e3de33bd746b
golang.org/x/oauth2@v0.8.0
0.27.0
1
istio/install-cni:1.10.32232f365aed6
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
1
istio/operator:1.10.3655eefa11c84
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
1
istio/operator:1.12.06cfce8a071b9
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0
1
istio/operator:1.18.270f9d1fe5fff
golang.org/x/oauth2@v0.7.0
0.27.0
1
istio/pilot:1.10.0294ca55bd1cc
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
1
istio/pilot:1.16.0ac0284d75ec9
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
1
istio/pilot:1.17.1ce9d87606701
golang.org/x/oauth2@v0.4.0
0.27.0
1
istio/pilot:1.15.2db08d6963975
golang.org/x/oauth2@v0.0.0-20220622183110-fd043fe589d2
0.27.0
1
istio/pilot:1.10.3e7e110a421c2
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
1
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
1
istio/proxyv2:1.10.088c6c693e67a
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
1
istio/proxyv2:1.14.1df69c1a7af7c
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
itzg/mc-router:1.16.1bb552b59fb53
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
jaegertracing/jaeger-operator:1.61.03f036ec60e61
golang.org/x/oauth2@v0.22.0
0.27.0
1
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
golang.org/x/oauth2@v0.23.0
0.27.0
1
jhonbrownn/elchi-discovery:latest8f6551ecc98c
golang.org/x/oauth2@v0.8.0
0.27.0
1
jkremser/log2rbac:v0.0.5e35cf56ef183
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0
1
juicedata/csi-dashboard:v0.23.03e4daf9626d5
golang.org/x/oauth2@v0.7.0
0.27.0
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
golang.org/x/oauth2@v0.7.0
0.27.0
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
golang.org/x/oauth2@v0.7.0
0.27.0
1
junktext/getting-started:1.0.5a70936c04aed
golang.org/x/oauth2@v0.3.0
0.27.0
1
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kaiso/kom-operator:v2.2.0e0e22b928bdd
golang.org/x/oauth2@v0.10.0
0.27.0
1
keelhq/keel:0.19.202ac4ea616c4
golang.org/x/oauth2@v0.7.0
0.27.0
1
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
golang.org/x/oauth2@v0.10.0
0.27.0
1
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
1
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
kronosorg/kronos-core:v0.4.0301da21c59a5
golang.org/x/oauth2@v0.12.0
0.27.0
1
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kserve/kserve-controller:v0.10.022ff858b57c1
golang.org/x/oauth2@v0.3.0
0.27.0
1
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.