StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,632
of 17,797 indexed, latest versions
Container images
2,029
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,632 of 17,797 indexed charts deploy, on 2,029 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,029
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,632 by stars
ChartLatestAffected imagesRadar Score
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

26,400
cachelavaOfficialVerified publisher1.1.11 of 1See more

cache lava 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/lavanet/lava/lavap:v2.5.089028adefcff
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,385
metallblectures-k8sinfra0.10.22 of 2See more

metallb lectures-k8sinfra 0.10.2

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.10.221164241c045
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/metallb/speaker:v0.10.258cb99053bb3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

5,406
prometheuslectures-k8sinfra15.8.54 of 6See more

prometheus lectures-k8sinfra 15.8.5

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
golang.org/x/oauth2@v0.0.0-20220628200809-02e64fa58f26
0.27.0

Open the chart page →

9,100
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

3,198
prometheusleechistest11.6.01 of 6See more

prometheus leechistest 11.6.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

8,492
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
golang.org/x/oauth2@v0.0.0-20220718184931-c8730f7fcb92
0.27.0

Open the chart page →

4,280
kltlifecycle-toolkitOfficialVerified publisher0.2.64 of 4See more

klt lifecycle-toolkit 0.2.6

4 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/keptn/certificate-operator:v1.1.08fdd311a6d33
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
ghcr.io/keptn/lifecycle-operator:v0.8.2487bfc37c4b4
golang.org/x/oauth2@v0.8.0
0.27.0
ghcr.io/keptn/metrics-operator:v0.8.2acf22310e9dd
golang.org/x/oauth2@v0.10.0
0.27.0
ghcr.io/keptn/scheduler:v0.8.20f7d277bb2b2
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

4,680
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,467
lightsteplightstep-microsat2.0.211 of 1See more

lightstep lightstep-microsat 2.0.21

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,127
linkerd-preview-vizlinkerd-buoyantVerified publisher25.4.34 of 5See more

linkerd-preview-viz linkerd-buoyant 25.4.3

4 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/metrics-api:preview-25.4.32cef2a3f97da
golang.org/x/oauth2@v0.25.0
0.27.0
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/buoyantio/tap:preview-25.4.3e02a8bd9e2c3
golang.org/x/oauth2@v0.25.0
0.27.0
ghcr.io/buoyantio/web:preview-25.4.33ee1b62aa111
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

3,454
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

2,136
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/session-manager-server:1.9.0f24ecd37fbaa
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

12,158
otlp-gatewayloafoe0.0.21 of 2See more

otlp-gateway loafoe 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

2,162
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

4,911
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

2,108
tempo-distributedloafoe1.20.11 of 2See more

tempo-distributed loafoe 1.20.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

2,027
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,519
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

7,544
central-hostpath-mapperloftVerified publisher0.2.91 of 1See more

central-hostpath-mapper loft 0.2.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/central-hostpath-mapper:0.2.9fa6dba122171
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

924
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,234
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

9,890
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,094
loft-agentloftVerified publisher3.2.41 of 1See more

loft-agent loft 3.2.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

2,453
loft-direct-cluster-endpointloftVerified publisher1.14.01 of 1See more

loft-direct-cluster-endpoint loft 1.14.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,119
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/oauth2@v0.17.0
0.27.0

Open the chart page →

3,234
vcluster-proloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

5,103
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.101 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

5,952
vcluster-pro-k0sloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro-k0s loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
golang.org/x/oauth2@v0.3.0
0.27.0
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

5,787
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.103 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/oauth2@v0.8.0
0.27.0
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

8,236
virtualclusterloftVerified publisher0.0.281 of 2See more

virtualcluster loft 0.0.28

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,993
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,525
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,501
nightingalelogic3579Verified publisher0.3.11 of 6See more

nightingale logic3579 0.3.1

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

9,096
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,508
apica-ascentlogiqai2.0.42 of 19See more

apica-ascent logiqai 2.0.4

2 of the 19 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
golang.org/x/oauth2@v0.16.0
0.27.0
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0

Open the chart page →

23,673
loxilbloxilbVerified publisher0.1.01 of 2See more

loxilb loxilb 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

4,529
lsdisklsdiskVerified publisher2.0.72 of 4See more

lsdisk lsdisk 2.0.7

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-provisioner:v5.0.27b9cdb5830d0
golang.org/x/oauth2@v0.20.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

5,053
chronograflsst-sqre1.3.51 of 1See more

chronograf lsst-sqre 1.3.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0

Open the chart page →

2,349
sasquatchlsst-sqre0.1.132 of 6See more

sasquatch lsst-sqre 0.1.13

2 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/kapacitor:1.6.37232f6388a4d
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0

Open the chart page →

9,348
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

6,649
telegraf-dslsst-sqre1.0.231 of 1See more

telegraf-ds lsst-sqre 1.0.23

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,773
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
golang.org/x/oauth2@v0.11.0
0.27.0

Open the chart page →

9,816
magistralamagistrala-devopsVerified publisher0.16.27 of 42See more

magistrala magistrala-devops 0.16.2

7 of the 42 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.31cc420186664
golang.org/x/oauth2@v0.18.0
0.27.0
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

24,566
kruisematrixone-operatorVerified publisher1.8.32 of 2See more

kruise matrixone-operator 1.8.3

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
openkruise/kruise-helm-hook:v0.1.0edc7cf9428fd
golang.org/x/oauth2@v0.17.0
0.27.0
openkruise/kruise-manager:v1.8.30482722b4e56
golang.org/x/oauth2@v0.17.0
0.27.0

Open the chart page →

1,775
mattermost-calls-offloadermattermostVerified publisher0.2.11 of 1See more

mattermost-calls-offloader mattermost 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mattermost/calls-offloader:v0.9.0b440b282599e
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,423
mattermost-push-proxymattermostVerified publisher0.14.31 of 1See more

mattermost-push-proxy mattermost 0.14.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mattermost/mattermost-push-proxy:6.3.045c53061c74e
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

897
mayastormayastorVerified publisher2.12.18 of 31See more

mayastor mayastor 2.12.1

8 of the 31 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:3.4.258a6c186ce78
golang.org/x/oauth2@v0.25.0
0.27.0
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/oauth2@v0.25.0
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/oauth2@v0.25.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/oauth2@v0.25.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/oauth2@v0.25.0
0.27.0
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

21,284
medewerkercatalogusmedewerkercatalogus1.0.01 of 3See more

medewerkercatalogus medewerkercatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,337
crdsmedia-streaming-meshVerified publisher0.0.11 of 2See more

crds media-streaming-mesh 0.0.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ciscolabs/msm-nc:0710202336d02faad958
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

3,724

Container images carrying it

2,029 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
twinproduction/aws-eks-asg-rolling-update-handler:v1.7.08f38c206972e
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
ubercadence/server:0.23.22ac5491d13bb
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
uffizzi/uffizzi-cluster-operator:v1.4.514e528bbd926
golang.org/x/oauth2@v0.4.0
0.27.0
1
uffizzi/uffizzi-cluster-operator:v1.6.55ca448a08783
golang.org/x/oauth2@v0.4.0
0.27.0
1
utho/utho-app-operator:0.1.46e8a690e8b7a
golang.org/x/oauth2@v0.21.0
0.27.0
1
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
golang.org/x/oauth2@v0.10.0
0.27.0
1
velero/velero:v1.9.0277fbfaf8dcf
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
velero/velero:v1.8.18d784580931c
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
victoriametrics/operator:v0.47.271be93cfafb6
golang.org/x/oauth2@v0.21.0
0.27.0
1
victoriametrics/victoria-metrics:v1.93.577a9815d0640
golang.org/x/oauth2@v0.12.0
0.27.0
1
victoriametrics/victoria-metrics:v1.95.1f52723a08a44
golang.org/x/oauth2@v0.14.0
0.27.0
1
victoriametrics/vmalert:v1.96.0150cd08fde94
golang.org/x/oauth2@v0.15.0
0.27.0
1
vikunja/api:0.17.18cba0520bf8c
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0
1
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
golang.org/x/oauth2@v0.13.0
0.27.0
1
vmware/kube-fluentd-operator:latestf028c138a5f4
golang.org/x/oauth2@v0.8.0
0.27.0
1
volcanosh/vc-controller-manager:v1.12.13815883c32f6
golang.org/x/oauth2@v0.23.0
0.27.0
1
volcanosh/vc-scheduler:v1.12.1b24ea8af2d16
golang.org/x/oauth2@v0.23.0
0.27.0
1
volcanosh/vc-webhook-manager:v1.12.1f8b50088a732
golang.org/x/oauth2@v0.23.0
0.27.0
1
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
voltha/bbsim-sadis-server:0.4.0762b272d439e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
vultr/vultr-cloud-controller-manager:v0.3.01806f17d620c
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
vultr/vultr-csi:v0.3.041d26735d437
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
wallarm/ebpf-agent:0.11.0-rc0c8920e60c726
golang.org/x/oauth2@v0.18.0
0.27.0
1
wallarm/ingress-controller:4.8.0-1a591b9c91570
golang.org/x/oauth2@v0.8.0
0.27.0
1
wallarm/kong-kubernetes-ingress-controller:2.8b55ff6cecbd5
golang.org/x/oauth2@v0.3.0
0.27.0
1
wateim/lighthouse-launch:latest2520149ee574
golang.org/x/oauth2@v0.23.0
0.27.0
1
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
wazuh/wazuh-manager:4.11.11da5c38c6a78
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
wazuh/wazuh-manager:4.4.121994f40e0da
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
wazuh/wazuh-manager:4.14.45a065930682d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
weaveworks/flagger:1.0.0-rc.5174307de1b36
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
weaveworks/flagger:0.19.0a9c2e9df4227
golang.org/x/oauth2@v0.0.0-20190402181905-9f3314589c9a
0.27.0
1
webdevops/azure-keyvault-exporter:24.9.1f333704ecd60
golang.org/x/oauth2@v0.23.0
0.27.0
1
webdevops/azure-scheduledevents-manager:24.9.0-kubernetes7acd46a8a972
golang.org/x/oauth2@v0.21.0
0.27.0
1
webdevops/kube-pool-manager:24.9.04fad7e14ad67
golang.org/x/oauth2@v0.23.0
0.27.0
1
weblate/weblate:3.11.3-182848df56ecd
golang.org/x/oauth2@v0.0.0-20181106182150-f42d05182288
0.27.0
1
wener/frpc:v0.37.0cc9fd4da44c0
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
wener/frps:v0.37.05c92cc9e8597
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0
1
wuhan005/forklift:daemon4e6da210e449
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
wuhan005/forklift:controllerbfbe82d59850
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
zufardhiyaulhaq/community-operator-v2:v1.0.07f1bbbe114eb
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
zufardhiyaulhaq/devopsweekly:v2.1.046625567fb60
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
zufardhiyaulhaq/goweekly:v2.0.008dcc130fbea
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
zufardhiyaulhaq/istio-ratelimit-operator:v2.15.0692cfc9d6614
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.