StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,713
of 17,828 indexed, latest versions
Container images
2,092
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,713 of 17,828 indexed charts deploy, on 2,092 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,092
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,713 by stars
ChartLatestAffected imagesRadar Score
commentopluspluswyrihaximusnetVerified publisher0.4.01 of 1See more

commentoplusplus wyrihaximusnet 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0

Open the chart page →

1,961
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

13,934
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,197
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kadalu/kadalu-operator:1.2.03726d7a805f2
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

4,928
nfs-subdir-external-provisionerxxl-job-adminVerified publisher4.0.181 of 1See more

nfs-subdir-external-provisioner xxl-job-admin 4.0.18

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,746
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

9,769
ygdrassil-monitoringygdrassilVerified publisher0.4.07 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

7 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
golang.org/x/oauth2@v0.25.0
0.27.0
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

9,530
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.12 of 4See more

rawfile-csi ymatrix 0.2.1

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

8,003
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,025
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/oauth2@v0.6.0
0.27.0
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

5,077
zahori-moonzahoriVerified publisher1.0.12 of 3See more

zahori-moon zahori 1.0.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/aerokube/moon:2.5.1a8837b00ba1c
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
quay.io/aerokube/moon-conf:2.5.19ca307b30080
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,908
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

3,702

Container images carrying it

2,092 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
1
istio/proxyv2:1.10.088c6c693e67a
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
1
istio/proxyv2:1.14.1df69c1a7af7c
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
itscontained/secret-manager:0.3.07ec3e93c6469
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
itzg/mc-router:1.16.1bb552b59fb53
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
jaegertracing/jaeger-operator:1.61.03f036ec60e61
golang.org/x/oauth2@v0.22.0
0.27.0
1
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
golang.org/x/oauth2@v0.23.0
0.27.0
1
jhonbrownn/elchi-discovery:latest8f6551ecc98c
golang.org/x/oauth2@v0.8.0
0.27.0
1
jkremser/log2rbac:v0.0.5e35cf56ef183
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0
1
juicedata/csi-dashboard:v0.23.03e4daf9626d5
golang.org/x/oauth2@v0.7.0
0.27.0
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
golang.org/x/oauth2@v0.7.0
0.27.0
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
golang.org/x/oauth2@v0.7.0
0.27.0
1
junktext/getting-started:1.0.5a70936c04aed
golang.org/x/oauth2@v0.3.0
0.27.0
1
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kadalu/kadalu-operator:1.2.03726d7a805f2
golang.org/x/oauth2@v0.8.0
0.27.0
1
kaiso/kom-operator:v2.2.0e0e22b928bdd
golang.org/x/oauth2@v0.10.0
0.27.0
1
keelhq/keel:0.19.202ac4ea616c4
golang.org/x/oauth2@v0.7.0
0.27.0
1
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
golang.org/x/oauth2@v0.10.0
0.27.0
1
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
1
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
kong/kubernetes-ingress-controller:3.1999213b98257
golang.org/x/oauth2@v0.16.0
0.27.0
1
kronosorg/kronos-core:v0.4.0301da21c59a5
golang.org/x/oauth2@v0.12.0
0.27.0
1
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kserve/kserve-controller:v0.10.022ff858b57c1
golang.org/x/oauth2@v0.3.0
0.27.0
1
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
kubebb/capsule-ce:v0.1.2-20221122a3dba2a95cef
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
1
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
kubebb/cert-manager-controller:v1.8.020509de4b399
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
kubebb/core:v0.1.62b9e7f451d6b
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0
1
kubebb/core:lateste366c34a9b8d
golang.org/x/oauth2@v0.13.0
0.27.0
1
kubebb/iam-controller:v0.2.0-202401288ffbfa2d67e9
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kubebb/iam-provider:v0.2.0-202401280ba03fcee3a7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kubebb/mesh-operator:v5.7.0163ebbfc7a82
golang.org/x/oauth2@v0.3.0
0.27.0
1
kubebb/oidc-server:v0.2.02b5894ef1e2f
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kubebb/resource-viewer:v0.2.065bb40b353db
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kubebuilder/kube-rbac-proxy:v0.16.03c4f708c6204
golang.org/x/oauth2@v0.10.0
0.27.0
1
kubedb/kubedb-enterprise:v0.11.05829bcedcb0d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.