StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,614
of 17,787 indexed, latest versions
Container images
1,999
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,614 of 17,787 indexed charts deploy, on 1,999 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.01,999
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,614 by stars
ChartLatestAffected imagesRadar Score
llo-apieclipse-aeriosVerified publisher1.0.01 of 1See more

llo-api eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
eclipseaerios/llo-api:1.2.0ab7a04182191
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

931
llo-docker-operatoreclipse-aeriosVerified publisher1.0.02 of 2See more

llo-docker-operator eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
eclipseaerios/llo-docker-operator:1.1.2d7ec28bfe735
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,187
llo-k8seclipse-aeriosVerified publisher1.1.02 of 2See more

llo-k8s eclipse-aerios 1.1.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,158
openfaas2eclipse-aeriosVerified publisher12.0.53 of 6See more

openfaas2 eclipse-aerios 12.0.5

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.51.24f6c47e39a90
golang.org/x/oauth2@v0.18.0
0.27.0
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

6,678
chartecr-toke-renew0.1.51 of 1See more

chart ecr-toke-renew 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,818
grafanaedu5.3.01 of 1See more

grafana edu 5.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

3,191
prometheusedu11.6.01 of 6See more

prometheus edu 11.6.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

8,484
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,327
cert-manager-cpanel-dns-webhookegebackVerified publisher1.0.61 of 1See more

cert-manager-cpanel-dns-webhook egeback 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,284
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
golang.org/x/oauth2@v0.24.0
0.27.0
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

3,866
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,510
ejabberdejabberdVerified publisher0.1.01 of 1See more

ejabberd ejabberd 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
indevlab/ejabberd:24.12-k8s8bc689d093a7
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

903
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,328
kube-ecp-stackemqx-operator2.5.110 of 16See more

kube-ecp-stack emqx-operator 2.5.1

10 of the 16 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
emqx/ecp-main:2.5.1fa876f71e5d6
golang.org/x/oauth2@v0.22.0
0.27.0
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/oauth2@v0.22.0
0.27.0
library/telegraf:1.27507a3eecf809
golang.org/x/oauth2@v0.11.0
0.27.0
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.1e2dc5623bcdd
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

23,685
cnpg-monitoringenixVerified publisher0.3.01 of 1See more

cnpg-monitoring enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

824
kube-packetloss-exporterenixVerified publisher0.2.12 of 2See more

kube-packetloss-exporter enix 0.2.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/oauth2@v0.21.0
0.27.0
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

6,131
monitoring-proxyenixVerified publisher0.3.01 of 2See more

monitoring-proxy enix 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,933
eoapi-supporteoapiVerified publisher0.1.76 of 7See more

eoapi-support eoapi 0.1.7

6 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:10.3.38640e5038e83
golang.org/x/oauth2@v0.15.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/oauth2@v0.10.0
0.27.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/oauth2@v0.8.0
0.27.0
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/oauth2@v0.10.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/oauth2@v0.8.0
0.27.0
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

8,648
epinio-uiepinioVerified publisher1.7.21 of 1See more

epinio-ui epinio 1.7.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/oauth2@v0.0.0-20220822191816-0ebed06d0094
0.27.0

Open the chart page →

1,684
upgrade-responderepinioVerified publisher0.2.01 of 5See more

upgrade-responder epinio 0.2.0

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:10.1.50679e877ba20
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

7,329
admin-console-operatorepmdedpVerified publisher2.14.02 of 2See more

admin-console-operator epmdedp 2.14.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/admin-console-operator:2.14.090f9921d8d58
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
epamedp/edp-admin-console:2.14.0616c678ba3e7
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,308
edp-argocd-operatorepmdedpVerified publisher0.2.01 of 1See more

edp-argocd-operator epmdedp 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/edp-argocd-operator:0.2.0976a662a5e72
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,574
edp-headlampepmdedpVerified publisher0.25.01 of 1See more

edp-headlamp epmdedp 0.25.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/edp-headlamp:0.25.093417e18bb1a
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,259
edp-tekton-interceptorepmdedpVerified publisher0.2.41 of 1See more

edp-tekton-interceptor epmdedp 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/edp-tekton:0.2.4924939850655
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

1,344
jenkins-operatorepmdedpVerified publisher2.15.31 of 3See more

jenkins-operator epmdedp 2.15.3

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.15.328ef56bc0ca3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,116
perf-operatorepmdedpVerified publisher2.13.01 of 1See more

perf-operator epmdedp 2.13.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/perf-operator:2.13.0bd2079b7bfcb
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

1,114
reconcilerepmdedpVerified publisher2.12.01 of 1See more

reconciler epmdedp 2.12.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/reconciler:2.12.0d33e938b6d59
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,180
tekton-custom-taskepmdedpVerified publisher0.2.01 of 1See more

tekton-custom-task epmdedp 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/tekton-custom-task:0.2.067d896676f45
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

549
codebase-operatorepmdedp-devVerified publisher2.12.0-MDTU-DDM-SNAPSHOT.101 of 1See more

codebase-operator epmdedp-dev 2.12.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,825
gerrit-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.21 of 1See more

gerrit-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,811
jenkins-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

jenkins-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,267
keycloak-operatorepmdedp-devVerified publisher1.11.0-MDTU-DDM-SNAPSHOT.101 of 1See more

keycloak-operator epmdedp-dev 1.11.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,234
chaos-meshethereum-helm-chartsVerified publisher0.0.31 of 4See more

chaos-mesh ethereum-helm-charts 0.0.3

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

12,127
testnet-homepageethereum-helm-chartsVerified publisher0.2.31 of 1See more

testnet-homepage ethereum-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

2,681
ingressmonitorcontrollerevilgn0me0.0.51 of 1See more

ingressmonitorcontroller evilgn0me 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/evilgn0me/ingressmonitorcontroller:v0.0.50bbfa4db14b9
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

576
preview-appsevilmartians0.4.01 of 1See more

preview-apps evilmartians 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.10.0b79e77d421d0
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

625
exa-csiexa-csi-driver0.2.0-rev25 of 6See more

exa-csi exa-csi-driver 0.2.0-rev2

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v4.5.19dcd469f02bb
golang.org/x/oauth2@v0.13.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/oauth2@v0.15.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
golang.org/x/oauth2@v0.13.0
0.27.0
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

7,048
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.02 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:2.9.66ca6e2cd3b6f
golang.org/x/oauth2@v0.10.0
0.27.0
grafana/loki-canary:2.9.6549a40203e97
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

5,748
faasnetfaasnet0.0.41 of 5See more

faasnet faasnet 0.0.4

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
simpleidserver/faasprometheus:0.0.425e378d57d78
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

7,617
mandefactlyVerified publisher0.5.161 of 3See more

mande factly 0.5.16

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
factly/mande-server:0.34.1384d384310ef
golang.org/x/oauth2@v0.2.0
0.27.0

Open the chart page →

4,777
oom-event-generatorfairwinds-incubator0.2.21 of 1See more

oom-event-generator fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

4,639
skopeo-syncfairwinds-incubator0.3.11 of 1See more

skopeo-sync fairwinds-incubator 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/skopeo/stable:v1.134853591bd1d2
golang.org/x/oauth2@v0.9.0
0.27.0

Open the chart page →

1,736
stackdriver-metrics-adapterfairwinds-incubator0.3.01 of 1See more

stackdriver-metrics-adapter fairwinds-incubator 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/gke-release/custom-metrics-stackdriver-adapter:v0.13.1-gke.06937c0a9b203
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

1,758
fake-network-operatorfake-network-operatorVerified publisher0.1.01 of 1See more

fake-network-operator fake-network-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/muhmmadayan/fake-network-operator:0.1.03806b1fd4a4b
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

495
farm-observabilityfarm-observabilityOfficialVerified publisher0.27.21 of 18See more

farm-observability farm-observability 0.27.2

1 of the 18 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

13,255
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0

Open the chart page →

13,450
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

7,481
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

14,673
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

3,311
grgatefikaworks0.3.41 of 1See more

grgate fikaworks 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,080

Container images carrying it

1,999 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
3
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/oauth2@v0.24.0
0.27.0
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0
3
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/oauth2@v0.18.0
0.27.0
3
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/oauth2@v0.23.0
0.27.0
3
grafana/loki:3.4.258a6c186ce78
golang.org/x/oauth2@v0.25.0
0.27.0
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
3
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/oauth2@v0.14.0
0.27.0
3
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/oauth2@v0.24.0
0.27.0
3
prom/prometheus:v3.0.1565ee8650122
golang.org/x/oauth2@v0.23.0
0.27.0
3
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
3
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/oauth2@v0.23.0
0.27.0
3
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/oauth2@v0.0.0-20191122200657-5d9234df094c
0.27.0
3
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/oauth2@v0.10.0
0.27.0
3
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/oauth2@v0.10.0
0.27.0
3
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/oauth2@v0.23.0
0.27.0
3
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/oauth2@v0.23.0
0.27.0
3
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
3
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
3
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/oauth2@v0.6.0
0.27.0
3
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/oauth2@v0.21.0
0.27.0
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
3
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
3
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
3
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/oauth2@v0.11.0
0.27.0
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/oauth2@v0.12.0
0.27.0
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/oauth2@v0.6.0
0.27.0
3
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/oauth2@v0.0.0-20181203162652-d668ce993890
0.27.0
3
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/oauth2@v0.22.0
0.27.0
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
3
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/oauth2@v0.5.0
0.27.0
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/oauth2@v0.8.0
0.27.0
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/oauth2@v0.8.0
0.27.0
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/oauth2@v0.19.0
0.27.0
3
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/oauth2@v0.3.0
0.27.0
3
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/oauth2@v0.23.0
0.27.0
3

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.