StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,614
of 17,787 indexed, latest versions
Container images
1,999
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,614 of 17,787 indexed charts deploy, on 1,999 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.01,999
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,614 by stars
ChartLatestAffected imagesRadar Score
llo-apieclipse-aeriosVerified publisher1.0.01 of 1See more

llo-api eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
eclipseaerios/llo-api:1.2.0ab7a04182191
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

931
llo-docker-operatoreclipse-aeriosVerified publisher1.0.02 of 2See more

llo-docker-operator eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
eclipseaerios/llo-docker-operator:1.1.2d7ec28bfe735
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,187
llo-k8seclipse-aeriosVerified publisher1.1.02 of 2See more

llo-k8s eclipse-aerios 1.1.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,158
openfaas2eclipse-aeriosVerified publisher12.0.53 of 6See more

openfaas2 eclipse-aerios 12.0.5

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.51.24f6c47e39a90
golang.org/x/oauth2@v0.18.0
0.27.0
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

6,678
chartecr-toke-renew0.1.51 of 1See more

chart ecr-toke-renew 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,818
grafanaedu5.3.01 of 1See more

grafana edu 5.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

3,191
prometheusedu11.6.01 of 6See more

prometheus edu 11.6.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

8,484
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,327
cert-manager-cpanel-dns-webhookegebackVerified publisher1.0.61 of 1See more

cert-manager-cpanel-dns-webhook egeback 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,284
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
golang.org/x/oauth2@v0.24.0
0.27.0
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

3,866
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,510
ejabberdejabberdVerified publisher0.1.01 of 1See more

ejabberd ejabberd 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
indevlab/ejabberd:24.12-k8s8bc689d093a7
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

903
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,328
kube-ecp-stackemqx-operator2.5.110 of 16See more

kube-ecp-stack emqx-operator 2.5.1

10 of the 16 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
emqx/ecp-main:2.5.1fa876f71e5d6
golang.org/x/oauth2@v0.22.0
0.27.0
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/oauth2@v0.22.0
0.27.0
library/telegraf:1.27507a3eecf809
golang.org/x/oauth2@v0.11.0
0.27.0
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.1e2dc5623bcdd
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

23,685
cnpg-monitoringenixVerified publisher0.3.01 of 1See more

cnpg-monitoring enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

824
kube-packetloss-exporterenixVerified publisher0.2.12 of 2See more

kube-packetloss-exporter enix 0.2.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/oauth2@v0.21.0
0.27.0
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

6,131
monitoring-proxyenixVerified publisher0.3.01 of 2See more

monitoring-proxy enix 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,933
eoapi-supporteoapiVerified publisher0.1.76 of 7See more

eoapi-support eoapi 0.1.7

6 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:10.3.38640e5038e83
golang.org/x/oauth2@v0.15.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/oauth2@v0.10.0
0.27.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/oauth2@v0.8.0
0.27.0
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/oauth2@v0.10.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/oauth2@v0.8.0
0.27.0
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

8,648
epinio-uiepinioVerified publisher1.7.21 of 1See more

epinio-ui epinio 1.7.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/oauth2@v0.0.0-20220822191816-0ebed06d0094
0.27.0

Open the chart page →

1,684
upgrade-responderepinioVerified publisher0.2.01 of 5See more

upgrade-responder epinio 0.2.0

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:10.1.50679e877ba20
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

7,329
admin-console-operatorepmdedpVerified publisher2.14.02 of 2See more

admin-console-operator epmdedp 2.14.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/admin-console-operator:2.14.090f9921d8d58
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
epamedp/edp-admin-console:2.14.0616c678ba3e7
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,308
edp-argocd-operatorepmdedpVerified publisher0.2.01 of 1See more

edp-argocd-operator epmdedp 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/edp-argocd-operator:0.2.0976a662a5e72
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,574
edp-headlampepmdedpVerified publisher0.25.01 of 1See more

edp-headlamp epmdedp 0.25.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/edp-headlamp:0.25.093417e18bb1a
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,259
edp-tekton-interceptorepmdedpVerified publisher0.2.41 of 1See more

edp-tekton-interceptor epmdedp 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/edp-tekton:0.2.4924939850655
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

1,344
jenkins-operatorepmdedpVerified publisher2.15.31 of 3See more

jenkins-operator epmdedp 2.15.3

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.15.328ef56bc0ca3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,116
perf-operatorepmdedpVerified publisher2.13.01 of 1See more

perf-operator epmdedp 2.13.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/perf-operator:2.13.0bd2079b7bfcb
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

1,114
reconcilerepmdedpVerified publisher2.12.01 of 1See more

reconciler epmdedp 2.12.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/reconciler:2.12.0d33e938b6d59
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,180
tekton-custom-taskepmdedpVerified publisher0.2.01 of 1See more

tekton-custom-task epmdedp 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/tekton-custom-task:0.2.067d896676f45
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

549
codebase-operatorepmdedp-devVerified publisher2.12.0-MDTU-DDM-SNAPSHOT.101 of 1See more

codebase-operator epmdedp-dev 2.12.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,825
gerrit-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.21 of 1See more

gerrit-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,811
jenkins-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

jenkins-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,267
keycloak-operatorepmdedp-devVerified publisher1.11.0-MDTU-DDM-SNAPSHOT.101 of 1See more

keycloak-operator epmdedp-dev 1.11.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,234
chaos-meshethereum-helm-chartsVerified publisher0.0.31 of 4See more

chaos-mesh ethereum-helm-charts 0.0.3

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

12,127
testnet-homepageethereum-helm-chartsVerified publisher0.2.31 of 1See more

testnet-homepage ethereum-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

2,681
ingressmonitorcontrollerevilgn0me0.0.51 of 1See more

ingressmonitorcontroller evilgn0me 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/evilgn0me/ingressmonitorcontroller:v0.0.50bbfa4db14b9
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

576
preview-appsevilmartians0.4.01 of 1See more

preview-apps evilmartians 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.10.0b79e77d421d0
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

625
exa-csiexa-csi-driver0.2.0-rev25 of 6See more

exa-csi exa-csi-driver 0.2.0-rev2

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v4.5.19dcd469f02bb
golang.org/x/oauth2@v0.13.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/oauth2@v0.15.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
golang.org/x/oauth2@v0.13.0
0.27.0
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

7,048
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.02 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:2.9.66ca6e2cd3b6f
golang.org/x/oauth2@v0.10.0
0.27.0
grafana/loki-canary:2.9.6549a40203e97
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

5,748
faasnetfaasnet0.0.41 of 5See more

faasnet faasnet 0.0.4

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
simpleidserver/faasprometheus:0.0.425e378d57d78
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

7,617
mandefactlyVerified publisher0.5.161 of 3See more

mande factly 0.5.16

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
factly/mande-server:0.34.1384d384310ef
golang.org/x/oauth2@v0.2.0
0.27.0

Open the chart page →

4,777
oom-event-generatorfairwinds-incubator0.2.21 of 1See more

oom-event-generator fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

4,639
skopeo-syncfairwinds-incubator0.3.11 of 1See more

skopeo-sync fairwinds-incubator 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/skopeo/stable:v1.134853591bd1d2
golang.org/x/oauth2@v0.9.0
0.27.0

Open the chart page →

1,736
stackdriver-metrics-adapterfairwinds-incubator0.3.01 of 1See more

stackdriver-metrics-adapter fairwinds-incubator 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/gke-release/custom-metrics-stackdriver-adapter:v0.13.1-gke.06937c0a9b203
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

1,758
fake-network-operatorfake-network-operatorVerified publisher0.1.01 of 1See more

fake-network-operator fake-network-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/muhmmadayan/fake-network-operator:0.1.03806b1fd4a4b
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

495
farm-observabilityfarm-observabilityOfficialVerified publisher0.27.21 of 18See more

farm-observability farm-observability 0.27.2

1 of the 18 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

13,255
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0

Open the chart page →

13,450
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

7,481
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

14,673
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

3,311
grgatefikaworks0.3.41 of 1See more

grgate fikaworks 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,080

Container images carrying it

1,999 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/oauth2@v0.6.0
0.27.0
3
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/oauth2@v0.22.0
0.27.0
3
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/oauth2@v0.18.0
0.27.0
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/oauth2@v0.8.0
0.27.0
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/oauth2@v0.18.0
0.27.0
3
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/oauth2@v0.21.0
0.27.0
3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/oauth2@v0.4.0
0.27.0
3
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/oauth2@v0.25.0
0.27.0
3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
3
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/oauth2@v0.25.0
0.27.0
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
3
alazidis/kube-netlag:1.1.00e8c84152201
golang.org/x/oauth2@v0.24.0
0.27.0
2
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/oauth2@v0.23.0
0.27.0
2
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
apecloud/apecloud-mcp:0.1.094041b080510
golang.org/x/oauth2@v0.25.0
0.27.0
2
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/oauth2@v0.15.0
0.27.0
2
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
2
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/oauth2@v0.3.0
0.27.0
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
datawire/aes:1.14.48588eafe6862
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/oauth2@v0.22.0
0.27.0
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/oauth2@v0.10.0
0.27.0
2
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/oauth2@v0.19.0
0.27.0
2
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/oauth2@v0.7.0
0.27.0
2
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/udm:v3.4.32f68df062a50
golang.org/x/oauth2@v0.15.0
0.27.0
2
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/oauth2@v0.8.0
0.27.0
2
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
2
governify/dashboard:lateste83a17ba5038
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0
2
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
2
grafana/grafana:9.2.4057896e23443
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.