StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,635
of 17,790 indexed, latest versions
Container images
2,033
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,635 of 17,790 indexed charts deploy, on 2,033 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,033
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,635 by stars
ChartLatestAffected imagesRadar Score
k8statusk8statusOfficialVerified publisher0.17.01 of 1See more

k8status k8status 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/stenic/k8status:0.17.093298e03089e
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

712
kiali-operatorkiali2.32.01 of 1See more

kiali-operator kiali 2.32.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/kiali/kiali-operator:v2.32.096c5264d54ab
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

1,085
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

7,303
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
neosu/kubebadges:v0.0.5256530d8e5c6
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,799
pyroscopekubeblocksVerified publisher0.2.921 of 1See more

pyroscope kubeblocks 0.2.92

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

1,620
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.04 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

11,675
prometheus-pingmesh-exporterkubservice-chartsVerified publisher1.1.11 of 1See more

prometheus-pingmesh-exporter kubservice-charts 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:latest355fa4be8e97
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

855
karporkusionstackVerified publisher0.7.61 of 3See more

karpor kusionstack 0.7.6

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

3,310
loftloftVerified publisher0.0.0-ci.141 of 1See more

loft loft 0.0.0-ci.14

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/oauth2@v0.9.0
0.27.0

Open the chart page →

3,686
vcluster-k8sloftVerified publisher0.0.0-ci.32 of 4See more

vcluster-k8s loft 0.0.0-ci.3

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

5,595
veleromesosphere3.2.51 of 1See more

velero mesosphere 3.2.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,871
kubecostmesosphere-stable0.37.57 of 9See more

kubecost mesosphere-stable 0.37.5

7 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
golang.org/x/oauth2@v0.10.0
0.27.0
grafana/grafana:9.4.71a359d92f40e
golang.org/x/oauth2@v0.3.0
0.27.0
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
golang.org/x/oauth2@v0.11.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.69.17bbe804260f3
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/thanos/thanos:v0.36.1e542959e1b36
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

17,799
rclonemglants2.3.41 of 1See more

rclone mglants 2.3.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,750
helm-ai-kernelmindburn-labsOfficialVerified publisher0.8.51 of 2See more

helm-ai-kernel mindburn-labs 0.8.5

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/helmdigest-pinned105741fa6621
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

2,175
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,803
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

5,066
secrets-injectoronepassword-connect1.2.01 of 1See more

secrets-injector onepassword-connect 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
1password/kubernetes-secrets-injector:1.0.25884757f7879
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

890
opentelemetry-ebpfopentelemetry-helmVerified publisher0.1.71 of 4See more

opentelemetry-ebpf opentelemetry-helm 0.1.7

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
otel/opentelemetry-ebpf-k8s-watcher:v0.10.263a0d1dd2cac
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

2,580
oesopsmxVerified publisher4.0.324 of 25See more

oes opsmx 4.0.32

4 of the 25 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
golang.org/x/oauth2@v0.0.0-20220822191816-0ebed06d0094
0.27.0
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

108,315
ipfs-clusterparadeum-teamVerified publisher0.0.191 of 2See more

ipfs-cluster paradeum-team 0.0.19

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.13.117259397f587
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

3,769
plecopleco0.24.01 of 1See more

pleco pleco 0.24.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,353
pomeriumpomerium34.0.11 of 1See more

pomerium pomerium 34.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

1,948
prometheus-systemd-exporterprometheus-communityVerified publisher0.5.21 of 1See more

prometheus-systemd-exporter prometheus-community 0.5.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/systemd-exporter:v0.7.078c03f875dfb
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

725
kube-prometheus-stackprometheus-worawutchan12.8.03 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0

Open the chart page →

12,132
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,731
seaweedfs-csi-driverseaweedfs-csi-driver0.2.383 of 7See more

seaweedfs-csi-driver seaweedfs-csi-driver 0.2.38

3 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/oauth2@v0.4.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/oauth2@v0.5.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

5,318
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

1,670
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

12,537
ingressmonitorcontrollerstakaterVerified publisher2.2.131 of 1See more

ingressmonitorcontroller stakater 2.2.13

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/stakater/ingressmonitorcontroller:v2.2.133301afb61c10
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

583
sn-platformstreamnative1.11.445 of 9See more

sn-platform streamnative 1.11.44

5 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/oauth2@v0.6.0
0.27.0
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

15,564
feedbacksystemthm-mni-iiVerified publisher0.47.13 of 10See more

feedbacksystem thm-mni-ii 0.47.1

3 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/oauth2@v0.15.0
0.27.0
library/docker:20.10.21-dind3153fa63f546
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

28,634
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,145
traefik-meshtraefikOfficialVerified publisher4.1.12 of 7See more

traefik-mesh traefik 4.1.1

2 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/traefik:v2.57d5a6ae66572
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

9,271
k8s-ttl-controllertwin0.4.01 of 1See more

k8s-ttl-controller twin 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

471
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
quay.io/argoproj/argocd:v2.8.6acaf37352569
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

10,373
vouchvouchVerified publisher3.2.01 of 1See more

vouch vouch 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

1,031
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,350
wallarm-ingresswallarmVerified publisher5.3.10-11 of 2See more

wallarm-ingress wallarm 5.3.10-1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,301
wallarm-sidecarwallarmOfficialVerified publisher6.13.11 of 3See more

wallarm-sidecar wallarm 6.13.1

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

965
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

6,085
wharf-helmwharf-helmOfficialVerified publisher3.2.62 of 5See more

wharf-helm wharf-helm 3.2.6

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

10,047
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,713
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

4,049
adcs-issueradcs-issuer3.0.21 of 1See more

adcs-issuer adcs-issuer 3.0.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
djkormo/adcs-issuer:2.1.29f34e87e7586
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

829
agentareaagentareaVerified publisher0.0.182 of 16See more

agentarea agentarea 0.0.18

2 of the 16 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/oauth2@v0.21.0
0.27.0
temporalio/auto-setup:1.29.15b3502a3b685
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

15,049
clearml-servingallegroaiVerified publisher1.6.23 of 9See more

clearml-serving allegroai 1.6.2

3 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/oauth2@v0.3.0
0.27.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

17,897
upcloud-csiankra-chartsVerified publisher0.4.06 of 8See more

upcloud-csi ankra-charts 0.4.0

6 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
golang.org/x/oauth2@v0.21.0
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0

Open the chart page →

14,969
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,149
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

3,395
anteonanteonVerified publisher2.6.43 of 13See more

anteon anteon 2.6.4

3 of the 13 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.64634b094b2183
golang.org/x/oauth2@v0.17.0
0.27.0
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
prom/prometheus:v2.37.98176adea328e
golang.org/x/oauth2@v0.0.0-20220628200809-02e64fa58f26
0.27.0

Open the chart page →

22,304

Container images carrying it

2,033 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
golang.org/x/oauth2@v0.11.0
0.27.0
1
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
golang.org/x/oauth2@v0.22.0
0.27.0
1
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
golang.org/x/oauth2@v0.19.0
0.27.0
1
ghcr.io/appscode/gh-ci-webhook:v0.0.2036ce246d884e
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/appscode/grafana:v2025.2.367d18880448c
golang.org/x/oauth2@v0.0.0-20210113205817-d3ed898aa8a3
0.27.0
1
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/appscode/kube-rbac-proxy:v0.15.0d8cc6ffb9819
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/appscode/license-proxyserver:v0.0.8d6c2532ea386
golang.org/x/oauth2@v0.15.0
0.27.0
1
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
golang.org/x/oauth2@v0.22.0
0.27.0
1
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/appscode/vcd-lb-gc:v0.1.0524c4045cd21
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/argelbargel/vault-raft-snapshot-agent:v0.12.5345174727a2b
golang.org/x/oauth2@v0.22.0
0.27.0
1
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
golang.org/x/oauth2@v0.18.0
0.27.0
1
ghcr.io/axonops/axonops-developer-operator:v0.1.0b3d6600c8ba5
golang.org/x/oauth2@v0.12.0
0.27.0
1
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
golang.org/x/oauth2@v0.4.0
0.27.0
1
ghcr.io/banzaicloud/kafka-operator:v0.20.2e341aefa9a90
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0
1
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/banzaicloud/logging-operator:3.17.623c2d4d54a64
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/banzaicloud/log-socket:latesta514736d2d4d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/benc-uk/kubeview:0.1.31f8e7cd7325a3
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
1
ghcr.io/bojanzelic/cloudflare-zero-trust-operator:0.7.1f4b2dbc19a78
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/browsersec/kubebrowse:sha-09dfa1fb853e9e6372a
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/buoyantio/metrics-api:preview-25.4.32cef2a3f97da
golang.org/x/oauth2@v0.25.0
0.27.0
1
ghcr.io/buoyantio/tap:preview-25.4.3e02a8bd9e2c3
golang.org/x/oauth2@v0.25.0
0.27.0
1
ghcr.io/buoyantio/web:preview-25.4.33ee1b62aa111
golang.org/x/oauth2@v0.25.0
0.27.0
1
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
golang.org/x/oauth2@v0.24.0
0.27.0
1
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
golang.org/x/oauth2@v0.24.0
0.27.0
1
ghcr.io/camptocamp/prometheus-puppetdb-sd:0.14.0414c0c99fd06
golang.org/x/oauth2@v0.25.0
0.27.0
1
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
golang.org/x/oauth2@v0.13.0
0.27.0
1
ghcr.io/caninehq/canine:latesta058034ca006
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/celestiaorg/celestia-app:v3.7.0-arabica23a9ec9b1879
golang.org/x/oauth2@v0.24.0
0.27.0
1
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/chaos-mesh/chaos-mesh:v2.7.28bc853c7414c
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
ghcr.io/ckotzbauer/access-managerdd584fcda0ff
golang.org/x/oauth2@v0.12.0
0.27.0
1
ghcr.io/ckotzbauer/chekrf299baf467b5
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.