StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,635
of 17,790 indexed, latest versions
Container images
2,033
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,635 of 17,790 indexed charts deploy, on 2,033 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,033
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,635 by stars
ChartLatestAffected imagesRadar Score
kubedb-provider-azureappscodeVerified publisher2026.7.101 of 1See more

kubedb-provider-azure appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

2,712
kubedb-provider-gcpappscodeVerified publisher2026.7.101 of 2See more

kubedb-provider-gcp appscode 2026.7.10

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

3,040
kubedb-ui-serverappscodeVerified publisher2021.12.211 of 1See more

kubedb-ui-server appscode 2021.12.21

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,054
kubeform-provider-awsappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-aws appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,803
kubeform-provider-azureappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-azure appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,724
kubeform-provider-gcpappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-gcp appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

2,750
kubevirt-infra-csi-driverappscodeVerified publisher0.1.01 of 6See more

kubevirt-infra-csi-driver appscode 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

1,209
kubevirt-tenant-csi-driverappscodeVerified publisher0.1.01 of 4See more

kubevirt-tenant-csi-driver appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,297
license-proxyserver-addon-managerappscodeVerified publisher2024.2.251 of 1See more

license-proxyserver-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.0.8d6c2532ea386
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,391
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

2,404
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

4,050
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

2,575
platform-linksappscodeVerified publisher2026.9.111 of 1See more

platform-links appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

778
service-providerappscodeVerified publisher2026.9.111 of 2See more

service-provider appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

2,238
stash-communityappscodeVerified publisher0.42.03 of 4See more

stash-community appscode 0.42.0

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/oauth2@v0.21.0
0.27.0
ghcr.io/stashed/stash:v0.42.03a98245a7667
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

3,669
statefulsetappscodeVerified publisher0.0.11 of 3See more

statefulset appscode 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,739
vcd-lb-gcappscodeVerified publisher2026.6.251 of 1See more

vcd-lb-gc appscode 2026.6.25

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/vcd-lb-gc:v0.1.0524c4045cd21
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

178
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

1,205
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0

Open the chart page →

5,211
argocdargo-helm-charts1.0.02 of 3See more

argocd argo-helm-charts 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/oauth2@v0.26.0
0.27.0
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

7,359
argonix-apiargonix0.2.31 of 4See more

argonix-api argonix 0.2.3

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

4,956
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

40,580
arma-reforgerarma-reforger0.5.36 of 8See more

arma-reforger arma-reforger 0.5.3

6 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
stakater/reloader:v1.0.15f4b87a8e56d4
golang.org/x/oauth2@v0.4.0
0.27.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/oauth2@v0.3.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

23,425
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,779
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

8,621
assemblylineassemblylineVerified publisher7.4.191 of 12See more

assemblyline assemblyline 7.4.19

1 of the 12 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

12,666
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0

Open the chart page →

18,357
performanceandusagediagnosisassist-iot-pud1.0.04 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

4 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/oauth2@v0.8.0
0.27.0
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

8,570
smartorchestratorassist-iot-smart-orchestrator4.0.01 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

1 of the 14 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

45,656
graph-nodeastria0.2.21 of 3See more

graph-node astria 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ipfs/kubo:v0.17.0803fac58ba15
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

5,547
sequencerastria4.0.01 of 3See more

sequencer astria 4.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0

Open the chart page →

6,335
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,570
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

5,082
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0

Open the chart page →

6,958
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,946
aws-node-termination-handler-2aws0.2.02 of 2See more

aws-node-termination-handler-2 aws 0.2.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/webhook:v2.0.0-beta86b0f7243250
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,966
aws-sigv4-proxy-admission-controlleraws0.1.21 of 1See more

aws-sigv4-proxy-admission-controller aws 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,140
axonops-developer-operatoraxonops-developer-operator0.1.01 of 1See more

axonops-developer-operator axonops-developer-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/axonops/axonops-developer-operator:v0.1.0b3d6600c8ba5
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

750
azure-advanced-backupazure-advanced-backup0.4.11 of 1See more

azure-advanced-backup azure-advanced-backup 0.4.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0

Open the chart page →

4,575
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

5,528
helm-controllerazureorkestra0.1.12 of 2See more

helm-controller azureorkestra 0.1.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
fluxcd/helm-controller:v0.9.092b891e495d8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
fluxcd/source-controller:v0.10.031a8c79a6803
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

7,723
keptn-addonsazureorkestra0.1.02 of 4See more

keptn-addons azureorkestra 0.1.0

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

10,629
prometheusazureorkestra14.8.01 of 6See more

prometheus azureorkestra 14.8.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0

Open the chart page →

9,669
krakendbaboulinet0.1.341 of 1See more

krakend baboulinet 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
devopsfaith/krakend:2.7.09219cda867e2
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

1,198
ragflowbaboulinet0.1.11 of 5See more

ragflow baboulinet 0.1.1

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-12-20T01-00-02Z5702ea361420
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

5,894
prometheus-blackbox-exporterbackbox-exporter7.8.01 of 1See more

prometheus-blackbox-exporter backbox-exporter 7.8.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.23.0ca04aa9d9093
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0

Open the chart page →

1,501
backlokto-operatorbacklokto0.0.11 of 1See more

backlokto-operator backlokto 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
piblokto/backlokto-operator:v0.0.20963cda71e393
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

694
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
conduction/balance-registration-php:devc36094a41369
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

8,417
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,352
trident-operatorberyju-org21.10.01 of 1See more

trident-operator beryju-org 21.10.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
netapp/trident-operator:21.10.049cfe552d9c2
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

2,078

Container images carrying it

2,033 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
zufardhiyaulhaq/devopsweekly:v2.1.046625567fb60
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
zufardhiyaulhaq/goweekly:v2.0.008dcc130fbea
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
zufardhiyaulhaq/istio-ratelimit-operator:v2.15.0692cfc9d6614
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
zufardhiyaulhaq/javascriptweekly:v2.1.086424bd0b2a4
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
zufardhiyaulhaq/kubernetesweekly:v2.1.0a287ada277c6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
zufardhiyaulhaq/ngrok-operator:v1.3.07cf2ae3fb1fb
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
golang.org/x/oauth2@v0.3.0
0.27.0
1
gcr.io/cadvisor/cadvisor:v0.52.1f40e65878e25
golang.org/x/oauth2@v0.24.0
0.27.0
1
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
golang.org/x/oauth2@v0.23.0
0.27.0
1
gcr.io/gke-release/custom-metrics-stackdriver-adapter:v0.13.1-gke.06937c0a9b203
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
gcr.io/gloo-mesh/gloo-mesh:1.1.2a4011eae6a0b
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0
1
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
gcr.io/istio-testing/operator:latest8d4576f7b98f
golang.org/x/oauth2@v0.21.0
0.27.0
1
gcr.io/k8s-staging-multitenancy/hnc-manager:v1.1.08ab8229f6a89
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
gcr.io/k8s-staging-sig-storage/objectstorage-controller:v20221027-v0.1.1-8-g300019fa84b574e8027
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/filterd675f211a40f
golang.org/x/oauth2@v0.22.0
0.27.0
1
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/ingressec4b544499ba
golang.org/x/oauth2@v0.22.0
0.27.0
1
gcr.io/knative-releases/knative.dev/eventing/cmd/mtchannel_broker395f4ff1bd34
golang.org/x/oauth2@v0.22.0
0.27.0
1
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhook873b968f02b5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.13.1a5b041ba3c9e
golang.org/x/oauth2@v0.16.0
0.27.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllere70bc675f977
golang.org/x/oauth2@v0.22.0
0.27.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook7d76a6d42d13
golang.org/x/oauth2@v0.22.0
0.27.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.13.1f066376eee17
golang.org/x/oauth2@v0.16.0
0.27.0
1
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourier15a601147ef4
golang.org/x/oauth2@v0.26.0
0.27.0
1
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourier197fbb71d1f1
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
gcr.io/knative-releases/knative.dev/operator/cmd/webhook6c5c90cdf707
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator08315309da4b
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator1e3db4f2eeed
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.13.121f8e11a44bf
golang.org/x/oauth2@v0.16.0
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activatora5de0fb75046
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.10.2c2994c2b6c2c
golang.org/x/oauth2@v0.1.0
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler105bdd14ecaa
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler2ef460356b17
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.13.134796e9f760b
golang.org/x/oauth2@v0.16.0
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.10.28319aa662b49
golang.org/x/oauth2@v0.1.0
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdb6ceff2aab4
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpa:v1.10.2eb612b929eaa
golang.org/x/oauth2@v0.1.0
0.27.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.