StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,713
of 17,828 indexed, latest versions
Container images
2,092
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,713 of 17,828 indexed charts deploy, on 2,092 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,092
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,713 by stars
ChartLatestAffected imagesRadar Score
commentopluspluswyrihaximusnetVerified publisher0.4.01 of 1See more

commentoplusplus wyrihaximusnet 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0

Open the chart page →

1,961
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

13,934
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,197
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kadalu/kadalu-operator:1.2.03726d7a805f2
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

4,928
nfs-subdir-external-provisionerxxl-job-adminVerified publisher4.0.181 of 1See more

nfs-subdir-external-provisioner xxl-job-admin 4.0.18

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,746
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

9,769
ygdrassil-monitoringygdrassilVerified publisher0.4.07 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

7 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
golang.org/x/oauth2@v0.25.0
0.27.0
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

9,530
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.12 of 4See more

rawfile-csi ymatrix 0.2.1

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

8,003
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,025
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/oauth2@v0.6.0
0.27.0
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

5,077
zahori-moonzahoriVerified publisher1.0.12 of 3See more

zahori-moon zahori 1.0.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/aerokube/moon:2.5.1a8837b00ba1c
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
quay.io/aerokube/moon-conf:2.5.19ca307b30080
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,908
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

3,702

Container images carrying it

2,092 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
kubedb/operator:v0.24.01a06ff0bda52
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kubeedge/edgemesh-agent:latest460c6061b608
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
kubeedge/edgemesh-server:latesta437cf5ec0ae
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kubeflowkatib/katib-controller:v0.17.072f14e03b9e1
golang.org/x/oauth2@v0.12.0
0.27.0
1
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kubeflowkatib/katib-ui:v0.17.07a41c508deb1
golang.org/x/oauth2@v0.12.0
0.27.0
1
kubeflownotebookswg/kfam:v1.9.22060a2ede788
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
kubeflownotebookswg/kfam:v1.6.1f226fb44db57
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
kubeflownotebookswg/notebook-controller:v1.9.20f14bd28fdd5
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kubeflownotebookswg/poddefaults-webhook:v1.6.17d42600e1524
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kubeflownotebookswg/poddefaults-webhook:v1.9.2bde88d98ad74
golang.org/x/oauth2@v0.8.0
0.27.0
1
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
kubeflownotebookswg/pvcviewer-controller:v1.9.29815e9b1728f
golang.org/x/oauth2@v0.19.0
0.27.0
1
kubeflownotebookswg/tensorboard-controller:v1.9.26536a9f61193
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kubeflownotebookswg/tensorboard-controller:v1.6.182ffdd2da285
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kubeflow/training-operator:v1-04f9f13dabb76dbda29
golang.org/x/oauth2@v0.12.0
0.27.0
1
kubeflow/training-operator:v1-e1434f6ff847e2b6af0
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
kubegems/chatgpt-api-proxy:latest8905c9dbbb5d
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
kubegems/ingress-nginx-operator:v0.2.0cc67357beeeb
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kubegems/kubectl:latestc3b4be9a54f5
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
kubegems/kube-rbac-proxy:v0.8.0941f557ed1ee
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
1
kubemod/kubemod:v0.19.11f8154f7e80c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
kubemod/kubemod:v0.13.0cadca39288ad
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
kuberay/operator:v1.0.04e6ac8a3a2c4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
kubernetesui/dashboard:v2.6.1290bebc3cd96
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
1
kubernetesui/dashboard:v2.7.02e500d29e9d5
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
1
kubernetesui/dashboard-api:1.7.060595892c2cf
golang.org/x/oauth2@v0.16.0
0.27.0
1
kubernetesui/dashboard-auth:1.1.307135c09e9ff
golang.org/x/oauth2@v0.16.0
0.27.0
1
kubernetesui/dashboard-metrics-scraper:1.1.17747d363c9fe
golang.org/x/oauth2@v0.12.0
0.27.0
1
kubernetesui/dashboard-web:1.4.04445b31a2c25
golang.org/x/oauth2@v0.16.0
0.27.0
1
kubernetesui/metrics-scraper:v1.0.876049887f07a
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
1
kubeshop/kube-webhook-certgen:0.0.7866827c379ae
golang.org/x/oauth2@v0.26.0
0.27.0
1
kubeshop/kusk-gateway:v1.5.48b5bfd57a3ce
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
1
kubeshop/kusk-gateway-api:v1.5.4126c713cf7d8
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
1
kubeshop/kusk-gateway-api-websocket:v1.5.43b4f8345ca5c
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
1
kubeshop/testkube-api-server:0.11.160ad97f07a78b
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
1
kubeshop/testkube-operator:2.1.154def0d0f0d4ab
golang.org/x/oauth2@v0.26.0
0.27.0
1
kubesphere/fluentbit-operator:v0.9.0b87db3c57cb3
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
kubesphere/fluent-operator:v1.0.2702df77228c6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kubesphere/ks-extensions-museum:latest29681958f220
golang.org/x/oauth2@v0.10.0
0.27.0
1
kubesphere/kubectl:v1.27.1649b445b1b732
golang.org/x/oauth2@v0.10.0
0.27.0
1
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
kubesphere/openelb:v0.4.4ed7311a0f9e4
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
kubesphere/porter:v0.4.38d1ed5ee1d2e
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
kubesphere/pvc-autoresizer:v0.19a18a16c7b87
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
kubesphere/storageclass-accessor:v0.1.1eac8f273a9b6
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.