CVE-2025-22868
HighAdvisory
Published 26 Feb 2025In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.009
- 56th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,633
- of 17,792 indexed, latest versions
- Container images
- 2,030
- deployed by those charts
- Fix available
- 1 of 1
- affected package
golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability
Carried by container images the latest versions of 1,633 of 17,792 indexed charts deploy, on 2,030 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more | 0.27.0 | 2,030 |
- OSV records
- GHSA-6v2p-p543-phr9
- Also known as
- GO-2025-3488
Charts affected
1,633 by stars
Container images carrying it
2,030 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | aa3df78ecf32 | golang.org/ | 0.27.0 | 1 |
| library/ | afa5d5134900 | golang.org/ | 0.27.0 | 1 |
| library/ | d9a0fd8bdd15 | golang.org/ | 0.27.0 | 1 |
| library/ | dd43b430341a | golang.org/ | 0.27.0 | 1 |
| library/ | 571eb4514977 | golang.org/ | 0.27.0 | 1 |
| library/ | a10d46445d68 | golang.org/ | 0.27.0 | 1 |
| library/ | ba10ac9ba17a | golang.org/ | 0.27.0 | 1 |
| library/ | d7f5dd5f70e2 | golang.org/ | 0.27.0 | 1 |
| library/ | 7232f6388a4d | golang.org/ | 0.27.0 | 1 |
| library/ | 28e98eece020 | golang.org/ | 0.27.0 | 1 |
| library/ | 507a3eecf809 | golang.org/ | 0.27.0 | 1 |
| library/ | 794079a7f241 | golang.org/ | 0.27.0 | 1 |
| library/ | addb86c0c520 | golang.org/ | 0.27.0 | 1 |
| library/ | 0a5157f742d2 | golang.org/ | 0.27.0 | 1 |
| library/ | 104204dadedf | golang.org/ | 0.27.0 | 1 |
| library/ | 1489caffaedb | golang.org/ | 0.27.0 | 1 |
| library/ | 1957e3314f43 | golang.org/ | 0.27.0 | 1 |
| library/ | 2f603f8d3abe | golang.org/ | 0.27.0 | 1 |
| library/ | 5d47b7bb2546 | golang.org/ | 0.27.0 | 1 |
| library/ | 7d0228d19042 | golang.org/ | 0.27.0 | 1 |
| library/ | eda951fd29a8 | golang.org/ | 0.27.0 | 1 |
| library/ | f5af5a5ce17f | golang.org/ | 0.27.0 | 1 |
| library/ | f98ac9dd97b0 | golang.org/ | 0.27.0 | 1 |
| lightstep/ | c800e05e1eff | golang.org/ | 0.27.0 | 1 |
| linuxserver/ | 45c5fe102ff3 | golang.org/ | 0.27.0 | 1 |
| litestream/ | c5a1e1b01916 | golang.org/ | 0.27.0 | 1 |
| livekit/ | ecf1409c75e0 | golang.org/ | 0.27.0 | 1 |
| loftsh/ | 310cc7d690f5 | golang.org/ | 0.27.0 | 1 |
| loftsh/ | 25deb9bd2683 | golang.org/ | 0.27.0 | 1 |
| loftsh/ | 023b13bf5898 | golang.org/ | 0.27.0 | 1 |
| logiqai/ | 65b996bc7bdc | golang.org/ | 0.27.0 | 1 |
| longhornio/ | dca34321452c | golang.org/ | 0.27.0 | 1 |
| longhornio/ | ede61fe2a472 | golang.org/ | 0.27.0 | 1 |
| louislam/ | 0b55bcb83a1c | golang.org/ | 0.27.0 | 1 |
| louislam/ | 96510915e6be | golang.org/ | 0.27.0 | 1 |
| louislam/ | a4eab252e5a2 | golang.org/ | 0.27.0 | 1 |
| louislam/ | a84767d7934f | golang.org/ | 0.27.0 | 1 |
| louislam/ | bc6f244ecf27 | golang.org/ | 0.27.0 | 1 |
| lumenvox/ | 9a69862e1248 | golang.org/ | 0.27.0 | 1 |
| macropower/ | 1e9c4fb89787 | golang.org/ | 0.27.0 | 1 |
| mantlenetworkio/ | 6bf383d14291 | golang.org/ | 0.27.0 | 1 |
| matrixdb/ | 7e9ffe249a51 | golang.org/ | 0.27.0 | 1 |
| matrixdb/ | ed3c7e6291e8 | golang.org/ | 0.27.0 | 1 |
| matrixdb/ | 95b2e38e913d | golang.org/ | 0.27.0 | 1 |
| mattermost/ | b440b282599e | golang.org/ | 0.27.0 | 1 |
| mattermost/ | 45c53061c74e | golang.org/ | 0.27.0 | 1 |
| mavrick1/ | 45ca0429a1d4 | golang.org/ | 0.27.0 | 1 |
| maxrocketinternet/ | 11224534789d | golang.org/ | 0.27.0 | 1 |
| mesosphere/ | b093d78a21ed | golang.org/ | 0.27.0 | 1 |
| mesosphere/ | 1b2dd9c0b0fc | golang.org/ | 0.27.0 | 1 |