StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,615
of 17,781 indexed, latest versions
Container images
2,001
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,615 of 17,781 indexed charts deploy, on 2,001 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,001
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,615 by stars
ChartLatestAffected imagesRadar Score
gateway-helmappscodeVerified publisher0.0.0-latest1 of 2See more

gateway-helm appscode 0.0.0-latest

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,057
scannerappscodeVerified publisher2026.1.151 of 3See more

scanner appscode 2026.1.15

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

5,299
smtprelayappscodeVerified publisher2026.9.111 of 1See more

smtprelay appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

840
stash-enterpriseappscodeVerified publisher0.42.03 of 4See more

stash-enterprise appscode 0.42.0

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/oauth2@v0.21.0
0.27.0
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

3,620
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

5,222
kedaarieotechVerified publisher0.1.02 of 3See more

keda arieotech 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.16.002348a19aeae
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,276
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0

Open the chart page →

2,819
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

10,730
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

4,292
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/oauth2@v0.0.0-20201203001011-0b49973bad19
0.27.0

Open the chart page →

3,391
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,814
chirpstackbeeinventor0.1.102 of 5See more

chirpstack beeinventor 0.1.10

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

7,807
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

1,595
helm-dashboardbeluga-cloudVerified publisher2.4.01 of 1See more

helm-dashboard beluga-cloud 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

2,898
boundaryboundary-chart0.3.121 of 1See more

boundary boundary-chart 0.3.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,624
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,830
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

2,042
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/oauth2@v0.0.0-20181003184128-c57b0facaced
0.27.0

Open the chart page →

2,663
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,483
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,483
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

906
capsulecapsuleOfficialVerified publisher0.14.51 of 2See more

capsule capsule 0.14.5

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,229
capsule-proxycapsule-proxyOfficialVerified publisher0.14.11 of 2See more

capsule-proxy capsule-proxy 0.14.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,222
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,509
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,799
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
golang.org/x/oauth2@v0.20.0
0.27.0
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

12,562
cert-manager-webhook-arvancloudcert-manager-webhook-arvancloudVerified publisher0.1.11 of 1See more

cert-manager-webhook-arvancloud cert-manager-webhook-arvancloud 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,067
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

1,024
cert-vaultcert-vaultOfficialVerified publisher2.12.01 of 7See more

cert-vault cert-vault 2.12.0

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

15,863
chatclichatcliVerified publisher1.203.01 of 2See more

chatcli chatcli 1.203.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,026
access-managerckotzbauerVerified publisher0.14.31 of 1See more

access-manager ckotzbauer 0.14.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/access-managerdigest-pinneddd584fcda0ff
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

643
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,268
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220201 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

1 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,256
cnpg-sandboxcloudnative-pgVerified publisher0.6.13 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

7,583
cloudttycloudtty0.8.91 of 2See more

cloudtty cloudtty 0.8.9

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell-operator:v0.8.9e43ad91f0684
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

3,951
cluster-setupcluster-setup1.5.01 of 8See more

cluster-setup cluster-setup 1.5.0

1 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

10,037
istio-allcode4devsVerified publisher1.2.04 of 6See more

istio-all code4devs 1.2.0

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/oauth2@v0.23.0
0.27.0
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
golang.org/x/oauth2@v0.19.0
0.27.0
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

4,784
istio-control-planecode4devsVerified publisher1.0.02 of 3See more

istio-control-plane code4devs 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/oauth2@v0.23.0
0.27.0
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,360
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,303
cosmo-controller-managercosmoVerified publisher0.9.01 of 2See more

cosmo-controller-manager cosmo 0.9.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-controller-manager:v0.9.08c7fa5552028
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,927
cosmo-dashboardcosmoVerified publisher0.9.11 of 1See more

cosmo-dashboard cosmo 0.9.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-dashboard:v0.9.16a1c4a81a924
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,939
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0

Open the chart page →

6,473
revadcs3orgOfficialVerified publisher1.6.11 of 1See more

revad cs3org 1.6.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

1,704
cubefscubefs3.2.05 of 10See more

cubefs cubefs 3.2.0

5 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0

Open the chart page →

15,891
CubeUniversecubeuniverseVerified publisher0.1.01 of 1See more

CubeUniverse cubeuniverse 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,837
cyphernetes-operatorcyphernetes-operatorVerified publisher0.1.01 of 1See more

cyphernetes-operator cyphernetes-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

498
aibrixdanchevVerified publisher0.7.02 of 5See more

aibrix danchev 0.7.0

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aibrix/controller-manager:v0.7.076aabbbfda79
golang.org/x/oauth2@v0.21.0
0.27.0
aibrix/gateway-plugins:v0.7.05b93ea4c753a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

5,274
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,759
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,568
dbrepodbrepo1.13.34 of 25See more

dbrepo dbrepo 1.13.3

4 of the 25 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
golang.org/x/oauth2@v0.23.0
0.27.0
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
golang.org/x/oauth2@v0.12.0
0.27.0
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
golang.org/x/oauth2@v0.8.0
0.27.0
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

52,635

Container images carrying it

2,001 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/oauth2@v0.24.0
0.27.0
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0
3
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/oauth2@v0.18.0
0.27.0
3
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/oauth2@v0.23.0
0.27.0
3
grafana/loki:3.4.258a6c186ce78
golang.org/x/oauth2@v0.25.0
0.27.0
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
3
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/oauth2@v0.14.0
0.27.0
3
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/oauth2@v0.24.0
0.27.0
3
prom/prometheus:v3.0.1565ee8650122
golang.org/x/oauth2@v0.23.0
0.27.0
3
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
3
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/oauth2@v0.23.0
0.27.0
3
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/oauth2@v0.0.0-20191122200657-5d9234df094c
0.27.0
3
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/oauth2@v0.10.0
0.27.0
3
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/oauth2@v0.10.0
0.27.0
3
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/oauth2@v0.23.0
0.27.0
3
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/oauth2@v0.23.0
0.27.0
3
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
3
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
3
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/oauth2@v0.6.0
0.27.0
3
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/oauth2@v0.21.0
0.27.0
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
3
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
3
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
3
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/oauth2@v0.11.0
0.27.0
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/oauth2@v0.12.0
0.27.0
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/oauth2@v0.6.0
0.27.0
3
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/oauth2@v0.0.0-20181203162652-d668ce993890
0.27.0
3
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/oauth2@v0.22.0
0.27.0
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
3
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/oauth2@v0.5.0
0.27.0
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/oauth2@v0.8.0
0.27.0
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/oauth2@v0.8.0
0.27.0
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/oauth2@v0.19.0
0.27.0
3
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/oauth2@v0.3.0
0.27.0
3
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/oauth2@v0.23.0
0.27.0
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
3

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.