StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,635
of 17,790 indexed, latest versions
Container images
2,033
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,635 of 17,790 indexed charts deploy, on 2,033 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,033
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,635 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

8,659
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,441
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,176
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

9,685
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

10,484
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

13,011
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,587
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

10,094
devtron-enterprisedevtron-labs48.0.09 of 28See more

devtron-enterprise devtron-labs 48.0.0

9 of the 28 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/oauth2@v0.11.0
0.27.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/oauth2@v0.1.0
0.27.0
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/oauth2@v0.0.0-20181203162652-d668ce993890
0.27.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

68,695
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

5,055
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

4,972
devtron-operatordevtron-labs0.23.35 of 11See more

devtron-operator devtron-labs 0.23.3

5 of the 11 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/oauth2@v0.1.0
0.27.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

33,180
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0

Open the chart page →

11,959
jcmhproxy-ingressdevtron-labs0.14.61 of 1See more

jcmhproxy-ingress devtron-labs 0.14.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

1,379
kube-prometheus-stackdevtron-labs19.3.03 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

8,659
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,441
winter-soldierdevtron-labs0.10.61 of 1See more

winter-soldier devtron-labs 0.10.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,176
digital-mobiusdigital-mobius0.1.41 of 1See more

digital-mobius digital-mobius 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
qoveryrd/digital-mobius:0.1.4b30a9398a83c
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,287
direktivdirektivVerified publisher0.10.03 of 6See more

direktiv direktiv 0.10.0

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-k8s:0.120.01e45d9483faa
golang.org/x/oauth2@v0.26.0
0.27.0
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.0aaafd456bda1
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

3,480
graphite-exporterdjjudas21Verified publisher0.1.91 of 1See more

graphite-exporter djjudas21 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/graphite-exporter:v0.16.0e54bca6645ea
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

782
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

17,053
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

4,224
dnation-kubernetes-monitoring-stackdnationcloud4.0.25 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

5 of the 17 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
golang.org/x/oauth2@v0.23.0
0.27.0
grafana/loki:3.2.0882e30c20683
golang.org/x/oauth2@v0.22.0
0.27.0
grafana/loki-canary:3.2.049e03f80d361
golang.org/x/oauth2@v0.22.0
0.27.0
prom/memcached-exporter:v0.15.0bb01ad25e9fc
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

21,744
ssl-exporterdnationcloud1.2.11 of 1See more

ssl-exporter dnationcloud 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
golang.org/x/oauth2@v0.0.0-20220630143837-2104d58473e0
0.27.0

Open the chart page →

1,632
dnsmasq-k8sdnsmasq-k8s1.4.11 of 1See more

dnsmasq-k8s dnsmasq-k8s 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

3,066
docker-authdocker-auth1.14.01 of 1See more

docker-auth docker-auth 1.14.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.14.098e0307e0d2d
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,514
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

8,417
furan2dollarshaveclubVerified publisher0.2.01 of 1See more

furan2 dollarshaveclub 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dollarshaveclub/furan2:master14a257836529
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,055
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

3,185
corednsdoubanVerified publisher1.39.21 of 1See more

coredns douban 1.39.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
coredns/coredns:1.12.040384aa1f5ea
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,139
gatekeeperdoubanVerified publisher3.17.12 of 3See more

gatekeeper douban 3.17.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.17.1b7b4d7cfdd52
golang.org/x/oauth2@v0.21.0
0.27.0
openpolicyagent/gatekeeper-crds:v3.17.177bc9bf3d163
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

2,499
k8s-crondoubanVerified publisher0.2.01 of 1See more

k8s-cron douban 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.28.2fc059f056ad0
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

3,668
tencentcloud-info-exporterdoubanVerified publisher0.2.21 of 1See more

tencentcloud-info-exporter douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

2,325
drogue-cloud-examplesdrogue-iotVerified publisher0.7.112 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

2 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
ghcr.io/ctron/kubectl:1.25e37d61b5277c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

30,753
drogue-cloud-metricsdrogue-iotVerified publisher0.7.112 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

2 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0

Open the chart page →

13,573
piraeusdtrdnk-helm-chartsVerified publisher2.2.01 of 1See more

piraeus dtrdnk-helm-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/piraeusdatastore/piraeus-operator:v2.2.0ec4022c8b0e3
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,042
tempo-operatordtrdnk-helm-chartsVerified publisher0.0.31 of 2See more

tempo-operator dtrdnk-helm-charts 0.0.3

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/grafana/tempo-operator/tempo-operator:v0.4.02627be646391
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

893
temporaldtrdnk-helm-chartsVerified publisher0.35.07 of 13See more

temporal dtrdnk-helm-charts 0.35.0

7 of the 13 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
temporalio/admin-tools:1.22.4258958fe2ff2
golang.org/x/oauth2@v0.11.0
0.27.0
temporalio/server:1.22.4c0a44c26397b
golang.org/x/oauth2@v0.4.0
0.27.0
temporalio/ui:2.16.2af9c9349708f
golang.org/x/oauth2@v0.6.0
0.27.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

20,240
duplicacyduplicacy0.1.21 of 2See more

duplicacy duplicacy 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
drumsergio/duplicacy-container:0.1.0dd3ee9703969
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,420
commentoduyet0.2.01 of 2See more

commento duyet 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/oauth2@v0.0.0-20180724155351-3d292e4d0cdc
0.27.0

Open the chart page →

2,679
kubernetes-database-scalerdvdlevanonVerified publisher0.1.21 of 1See more

kubernetes-database-scaler dvdlevanon 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dvdlevanon/kubernetes-database-scaler:v0.0.361e79c1643fe4
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

1,023
ai-scale-authdysnixVerified publisher0.1.12 of 3See more

ai-scale-auth dysnix 0.1.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alex6021710/ai-scale-auth:latest6c7a47e470c3
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
alex6021710/ai-scale-migrator:latest744b8a924f35
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

6,155
ai-scale-doerdysnixVerified publisher0.1.01 of 1See more

ai-scale-doer dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alex6021710/ai-scale-doer:latest31e533cf7cd3
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0

Open the chart page →

2,807
ai-scale-providerdysnixVerified publisher0.1.01 of 1See more

ai-scale-provider dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alex6021710/ai-scale-provider:latest5837d9b30cc7
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

2,185
ai-scale-saverdysnixVerified publisher0.1.01 of 1See more

ai-scale-saver dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alex6021710/ai-scale-saver:latestf73e8d60fd03
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

2,142
bordysnixVerified publisher0.0.81 of 1See more

bor dysnix 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
0xpolygon/bor:1.3.7396d3de26d8b
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

1,372
gcp-local-ssd-raiddysnixVerified publisher0.1.71 of 2See more

gcp-local-ssd-raid dysnix 0.1.7

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

2,410
gke-upgrade-notification-handlerdysnixVerified publisher0.1.11 of 1See more

gke-upgrade-notification-handler dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dysnix/gke-upgrade-notification-handler:latestc166f958f86a
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

2,097
grafana-dashboardsdysnixVerified publisher0.2.21 of 2See more

grafana-dashboards dysnix 0.2.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.4.5d322192ed2fa
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0

Open the chart page →

5,167
heimdalldysnixVerified publisher0.0.11 of 1See more

heimdall dysnix 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
0xpolygon/heimdall:1.0.134ddf259993c
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

1,373

Container images carrying it

2,033 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
1
owncloud/server:10.15.051d9b74fc2a8
golang.org/x/oauth2@v0.21.0
0.27.0
1
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
pannoi/kollektor:1.0.59559617788fc
golang.org/x/oauth2@v0.8.0
0.27.0
1
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
golang.org/x/oauth2@v0.15.0
0.27.0
1
phntom/chartmuseum:v0.16.053883b65d9b7
golang.org/x/oauth2@v0.7.0
0.27.0
1
phntom/chartmuseum:v0.15.29242b4df9e65
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
1
phntom/external-dns-host-network:0.0.123adadbac8443
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/oauth2@v0.8.0
0.27.0
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
photoprism/photoprism:240711-cefc6fd632ca74
golang.org/x/oauth2@v0.21.0
0.27.0
1
piblokto/backlokto-operator:v0.0.20963cda71e393
golang.org/x/oauth2@v0.8.0
0.27.0
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
golang.org/x/oauth2@v0.23.0
0.27.0
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
golang.org/x/oauth2@v0.6.0
0.27.0
1
polyaxon/training-operator:2.1.0b5b29deaec9a
golang.org/x/oauth2@v0.8.0
0.27.0
1
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/oauth2@v0.7.0
0.27.0
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0
1
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
1
projecthami/volcano-vgpu-device-plugin:v1.9.40c94118d1d98
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
prom/blackbox-exporter:v0.22.0608acee5704a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
golang.org/x/oauth2@v0.18.0
0.27.0
1
prom/blackbox-exporter:v0.23.0ca04aa9d9093
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
1
prom/consul-exporter:v0.13.04e4cfd809e96
golang.org/x/oauth2@v0.23.0
0.27.0
1
prometheuscommunity/postgres-exporter:v0.17.0f8381eb4326a
golang.org/x/oauth2@v0.24.0
0.27.0
1
prom/graphite-exporter:v0.16.0e54bca6645ea
golang.org/x/oauth2@v0.23.0
0.27.0
1
prom/memcached-exporter:v0.15.0bb01ad25e9fc
golang.org/x/oauth2@v0.23.0
0.27.0
1
prom/node-exporter:v1.6.0d2e48098c364
golang.org/x/oauth2@v0.8.0
0.27.0
1
prom/prometheus:v2.51.24f6c47e39a90
golang.org/x/oauth2@v0.18.0
0.27.0
1
prom/prometheus:v2.18.15880ec936055
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
prom/prometheus:v2.48.0b440bc0e8aa5
golang.org/x/oauth2@v0.13.0
0.27.0
1
prom/prometheus:v2.19.2cd134bd4fca0
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
prom/prometheus:v2.16.0e4ca62c0d62f
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
prom/prometheus:v2.22.2f7ffebdd428b
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
1
prom/pushgateway:v1.4.33496e0f85943
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
prom/statsd-exporter:v0.24.061d866e93b56
golang.org/x/oauth2@v0.8.0
0.27.0
1
promzeus/redis-sentinel-gateway:v182f6d56e280b
golang.org/x/oauth2@v0.21.0
0.27.0
1
qoveryrd/digital-mobius:0.1.4b30a9398a83c
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
qumine/ingress-controller:v0.8.5f2c8a2148381
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0
1
rabbitmqoperator/cluster-operator:2.6.08651dd3cec51
golang.org/x/oauth2@v0.8.0
0.27.0
1
rancher/hardened-calico:v3.13.36d2cd61a338b
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
golang.org/x/oauth2@v0.0.0-20170629032740-5432cc9688e6
0.27.0
1
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
1
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
rancher/k3s:v1.28.2-k3s18c2599ecfca8
golang.org/x/oauth2@v0.11.0
0.27.0
1
rancher/k3s:v1.25.3-k3s1eaa270df79cc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
rancher/local-path-provisioner:v0.0.309b9148811700
golang.org/x/oauth2@v0.10.0
0.27.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.