StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,632
of 17,797 indexed, latest versions
Container images
2,029
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,632 of 17,797 indexed charts deploy, on 2,029 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,029
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,632 by stars
ChartLatestAffected imagesRadar Score
promtailkube-opsVerified publisher1.5.11 of 2See more

promtail kube-ops 1.5.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/kube-ops/promtail:2.2.134de6387233b
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0

Open the chart page →

4,157
kubereportkubereport1.1.01 of 1See more

kubereport kubereport 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesuite/kubereport:latest0262424ee702
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,120
scrutinykubernetes-homelab-helm-chartsVerified publisher0.2.21 of 3See more

scrutiny kubernetes-homelab-helm-charts 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/influxdb:2.8571eb4514977
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

5,551
brudi-operatorkubernetes-replicator0.2.31 of 1See more

brudi-operator kubernetes-replicator 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

3,631
harbor-operatorkubernetes-replicator1.6.31 of 1See more

harbor-operator kubernetes-replicator 1.6.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/mittwald/harbor-operator:v1.6.365a38180e27a
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

1,205
kubernetes-secret-generatorkubernetes-replicator3.4.11 of 1See more

kubernetes-secret-generator kubernetes-replicator 3.4.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-secret-generator:v3.4.1465b8e6d0462
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

855
kubernetesweeklykubernetesweekly2.1.01 of 1See more

kubernetesweekly kubernetesweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
zufardhiyaulhaq/kubernetesweekly:v2.1.0a287ada277c6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,489
kube-secrets-exporterkube-secrets-exporter0.1.01 of 1See more

kube-secrets-exporter kube-secrets-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/dcristobalhmad/kube-secrets-exporter:latesta9043737cb73
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

544
api-serverkubeshop0.11.161 of 2See more

api-server kubeshop 0.11.16

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeshop/testkube-api-server:0.11.160ad97f07a78b
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

3,432
kusk-gatewaykubeshop0.0.651 of 2See more

kusk-gateway kubeshop 0.0.65

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeshop/kusk-gateway:v1.5.48b5bfd57a3ce
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0

Open the chart page →

1,622
kusk-gateway-apikubeshop0.1.282 of 2See more

kusk-gateway-api kubeshop 0.1.28

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeshop/kusk-gateway-api:v1.5.4126c713cf7d8
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
kubeshop/kusk-gateway-api-websocket:v1.5.43b4f8345ca5c
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0

Open the chart page →

2,308
testkube-operatorkubeshop2.1.1542 of 3See more

testkube-operator kubeshop 2.1.154

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeshop/kube-webhook-certgen:0.0.7866827c379ae
golang.org/x/oauth2@v0.26.0
0.27.0
kubeshop/testkube-operator:2.1.154def0d0f0d4ab
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

1,011
cloudnative-pgkube-site-follower0.23.01 of 1See more

cloudnative-pg kube-site-follower 0.23.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

909
apisix-ingress-controllerkubesphereVerified publisher0.8.01 of 2See more

apisix-ingress-controller kubesphere 0.8.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apache/apisix-ingress-controller:1.3.0412f92cde0b3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,409
fluentbit-operatorkubesphereVerified publisher0.1.01 of 2See more

fluentbit-operator kubesphere 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/fluentbit-operator:v0.9.0b87db3c57cb3
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,902
gitlabkubesphereVerified publisher4.2.34 of 17See more

gitlab kubesphere 4.2.3

4 of the 17 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:alpine-v13.2.1fd7e5dfb9f30
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

38,190
harborkubesphereVerified publisher1.9.37 of 11See more

harbor kubesphere 1.9.3

7 of the 11 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
goharbor/chartmuseum-photon:v2.5.36ab3ca28e9e5
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
goharbor/harbor-core:v2.5.386bf3031f4a7
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

17,853
pvc-autoresizerkubesphereVerified publisher0.1.01 of 1See more

pvc-autoresizer kubesphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/pvc-autoresizer:v0.19a18a16c7b87
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,563
storageclass-accessorkubesphereVerified publisher0.1.01 of 1See more

storageclass-accessor kubesphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/storageclass-accessor:v0.1.1eac8f273a9b6
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

1,510
chaos-meshkubesphere-stable2.5.13 of 3See more

chaos-mesh kubesphere-stable 2.5.1

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

8,582
cni-hostnickubesphere-stable0.1.01 of 1See more

cni-hostnic kubesphere-stable 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,444
cranekubesphere-stable0.5.23 of 3See more

crane kubesphere-stable 0.5.2

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gocrane/crane-scheduler:0.0.239ba6d11b2079
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gocrane/crane-scheduler-controller:0.1.23a2d7e60576f9
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gocrane/craned:v0.5.1a1400909118c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

8,903
csi-qingcloudkubesphere-stable1.4.05 of 6See more

csi-qingcloud kubesphere-stable 1.4.0

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0

Open the chart page →

12,446
deepflowkubesphere-stable6.2.6062 of 8See more

deepflow kubesphere-stable 6.2.606

2 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
golang.org/x/oauth2@v0.4.0
0.27.0
grafana/grafana:9.5.239c849cebccc
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

18,435
edgemeshkubesphere-stable0.1.02 of 2See more

edgemesh kubesphere-stable 0.1.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeedge/edgemesh-agent:latest460c6061b608
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
kubeedge/edgemesh-server:latesta437cf5ec0ae
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

4,108
fpga-operatorkubesphere-stable2.7.41 of 7See more

fpga-operator kubesphere-stable 2.7.4

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
inaccel/reef:latestc967218739f3
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

5,771
iomeshkubesphere-stable1.1.019 of 25See more

iomesh kubesphere-stable 1.1.0

19 of the 25 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.1.0d86dab5611a7
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
iomesh/blockdevice-monitor-prober:v0.1.0584dbe19db7e
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
iomesh/csi-driver:v2.7.25d3f9bf9240b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
iomesh/csi-snapshotter:v6.2.2becc53e25b96
golang.org/x/oauth2@v0.1.0
0.27.0
iomesh/deck:v0.1.0a31e26b6ae22
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/deck-plugin-iomesh:v0.1.00b13bf217110
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/localpv-manager:v0.2.0f13deacac3f4
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
iomesh/node-disk-exporter:1.8.0f03148764f38
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/node-disk-manager:1.8.0002c4b92fd34
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/node-disk-operator:1.8.0f6c76380db34
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/operator:v1.1.060081c9b2f52
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/post-delete-hook:v1.1.0eea5651f3270
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
golang.org/x/oauth2@v0.1.0
0.27.0
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/oauth2@v0.4.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/oauth2@v0.5.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

49,004
IOMeshkubesphere-stable1.2.019 of 25See more

IOMesh kubesphere-stable 1.2.0

19 of the 25 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
iomesh/blockdevice-monitor-prober:v0.2.1026a1d87f6e9
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
iomesh/csi-driver:v2.8.01a151f602451
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
iomesh/csi-snapshotter:v6.2.2becc53e25b96
golang.org/x/oauth2@v0.1.0
0.27.0
iomesh/deck:v0.2.0282d6c419ed3
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/deck-plugin-iomesh:v0.2.0df149e4ab39f
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/localpv-manager:v0.2.0f13deacac3f4
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
iomesh/node-disk-exporter:1.8.0f03148764f38
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/node-disk-manager:1.8.0-2292ad270082e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/operator:v1.2.0ba4dd6be7e59
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/post-delete-hook:v1.2.0e3b92f838f4b
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
golang.org/x/oauth2@v0.1.0
0.27.0
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/oauth2@v0.4.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/oauth2@v0.5.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

46,692
pulsarkubesphere-stable2.7.132 of 3See more

pulsar kubesphere-stable 2.7.13

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0

Open the chart page →

14,457
cni-hostnickubesphere-testVerified publisher0.1.01 of 1See more

cni-hostnic kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,444
csi-neonsankubesphere-testVerified publisher1.3.05 of 6See more

csi-neonsan kubesphere-test 1.3.0

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0

Open the chart page →

18,537
csi-qingcloudkubesphere-testVerified publisher1.4.05 of 6See more

csi-qingcloud kubesphere-test 1.4.0

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0

Open the chart page →

12,446
online-boutiquekubesphere-testVerified publisher0.1.04 of 11See more

online-boutique kubesphere-test 0.1.0

4 of the 11 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

26,079
openelbkubesphere-testVerified publisher0.2.42 of 2See more

openelb kubesphere-test 0.2.4

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.4.4ed7311a0f9e4
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

4,336
porterkubesphere-testVerified publisher0.2.21 of 2See more

porter kubesphere-test 0.2.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/porter:v0.4.38d1ed5ee1d2e
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,791
snapshot-controllerkubesphere-testVerified publisher0.2.01 of 1See more

snapshot-controller kubesphere-test 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0

Open the chart page →

2,220
kubestellar-consolekubestellar-consoleVerified publisher0.3.412 of 2See more

kubestellar-console kubestellar-console 0.3.41

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.32.47e1e7d5b7a96
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/kubestellar/console:v0.3.41457cfc94b4da
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

4,458
kubestellar-uikubestellaruiVerified publisher0.1.11 of 4See more

kubestellar-ui kubestellarui 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mavrick1/kubestellar-b:latest45ca0429a1d4
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

4,778
kube-workload-restarterkube-workload-restarterVerified publisher0.0.41 of 1See more

kube-workload-restarter kube-workload-restarter 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
andreacioni/kube-workload-restarter:0.0.242938b310090a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,815
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.45 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

5 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/kubiyabot/kubiya-operator:runner_v26bf945565865
golang.org/x/oauth2@v0.22.0
0.27.0
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
golang.org/x/oauth2@v0.10.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

20,435
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

3,477
kuperatorkusionstackVerified publisher0.7.41 of 1See more

kuperator kusionstack 0.7.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kusionstack/kuperator:v0.7.4d2f72ae1d2f2
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

980
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

6,969
operatingkusionstackVerified publisher0.5.11 of 1See more

operating kusionstack 0.5.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kusionstack/operating:v0.5.0c28bd96b986b
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,881
sample-operatorkusionstackVerified publisher0.1.21 of 1See more

sample-operator kusionstack 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
chaerr/kridge:demo-operator-v0.1.266833deec017
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

2,511
dynatrace-operatorkvalitetsitVerified publisher1.3.01 of 1See more

dynatrace-operator kvalitetsit 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.3.0f68901a54664
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

1,320
krakendkvalitetsitVerified publisher0.0.31 of 1See more

krakend kvalitetsit 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

1,249
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

16,561
metadockvalitetsitVerified publisher0.0.72 of 2See more

metadoc kvalitetsit 0.0.7

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-app:maine89e351733ad
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0

Open the chart page →

4,033
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

8,544

Container images carrying it

2,029 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
su541/cert-manager-desec-webhook:latest371ee33f83c1
golang.org/x/oauth2@v0.4.0
0.27.0
1
summerwind/actions-runner-controller:v0.27.62128f81dbede
golang.org/x/oauth2@v0.7.0
0.27.0
1
supabase/gotrue:v2.91.07174d551d720
golang.org/x/oauth2@v0.6.0
0.27.0
1
supabase/gotrue:v2.163.0ba4ddc594b0b
golang.org/x/oauth2@v0.17.0
0.27.0
1
surajwarbhe/grafana:v185248611e9f1
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
golang.org/x/oauth2@v0.6.0
0.27.0
1
sysintelligent/hello-app:2.0.177fb30df847d
golang.org/x/oauth2@v0.12.0
0.27.0
1
tailscale/k8s-operator:v1.70.08edd06cf5bac
golang.org/x/oauth2@v0.16.0
0.27.0
1
tailwarden/komiser:3.1.103f68c8ae7993
golang.org/x/oauth2@v0.13.0
0.27.0
1
tdengine/tdengine:3.0.2.24140a4021ddb
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
1
tdeutsch/podsync:v2.4.2b67186f4c9a5
golang.org/x/oauth2@v0.0.0-20180620175406-ef147856a6dd
0.27.0
1
temporalio/admin-tools:1.22.4258958fe2ff2
golang.org/x/oauth2@v0.11.0
0.27.0
1
temporalio/admin-tools:1.15.135034611d981
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
temporalio/admin-tools:1.26.237e2e33dbd7b
golang.org/x/oauth2@v0.7.0
0.27.0
1
temporalio/admin-tools:1.22.0836af062af30
golang.org/x/oauth2@v0.4.0
0.27.0
1
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
golang.org/x/oauth2@v0.7.0
0.27.0
1
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
golang.org/x/oauth2@v0.20.0
0.27.0
1
temporalio/admin-tools:1.28cfde8170c92f
golang.org/x/oauth2@v0.7.0
0.27.0
1
temporalio/auto-setup:1.29.15b3502a3b685
golang.org/x/oauth2@v0.7.0
0.27.0
1
temporalio/auto-setup:1.27.2b44cbfeb43db
golang.org/x/oauth2@v0.26.0
0.27.0
1
temporalio/server:1.26.21e2626efcbc1
golang.org/x/oauth2@v0.23.0
0.27.0
1
temporalio/server:1.25.08a5798191dea
golang.org/x/oauth2@v0.20.0
0.27.0
1
temporalio/server:1.29.1c1e3326b2ce1
golang.org/x/oauth2@v0.7.0
0.27.0
1
temporalio/server:1.22.0ddeebf8bad8f
golang.org/x/oauth2@v0.4.0
0.27.0
1
temporalio/server:1.15.1e26758f5a1bf
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
temporalio/ui:2.30.25c2a3645d09c
golang.org/x/oauth2@v0.22.0
0.27.0
1
temporalio/ui:2.33.05c586a3c8ec5
golang.org/x/oauth2@v0.22.0
0.27.0
1
thanosio/thanos:v0.19.088276fcd1491
golang.org/x/oauth2@v0.0.0-20210210192628-66670185b0cd
0.27.0
1
thanosio/thanos:v0.15.0b12d5c31bf5a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0
1
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
thomseddon/traefik-forward-auth:latestb364aa6a4117
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
tile38/tile38:1.33.4afb7e82f9485
golang.org/x/oauth2@v0.13.0
0.27.0
1
timescale/timescaledb-ha:pg16d7db8f1085a3
golang.org/x/oauth2@v0.19.0
0.27.0
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
golang.org/x/oauth2@v0.21.0
0.27.0
1
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
tobirachel/node-project3:v17d9f37154994
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
toucansoftware/spa-reloader:latestc187b1fba501
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
tranhailong/nfs-server:4.2-2-gcsfuse028662749be2
golang.org/x/oauth2@v0.3.0
0.27.0
1
treeverse/lakefs:0.69.0478f37a6cffc
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
tusproject/tusd:v1.10.01e457b59fd5b
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
1
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/oauth2@v0.11.0
0.27.0
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.