StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,614
of 17,787 indexed, latest versions
Container images
1,999
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,614 of 17,787 indexed charts deploy, on 1,999 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.01,999
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,614 by stars
ChartLatestAffected imagesRadar Score
grafana-cloud-onboardinggrafana0.4.71 of 5See more

grafana-cloud-onboarding grafana 0.4.7

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

4,637
grafana-samplinggrafana1.1.71 of 2See more

grafana-sampling grafana 1.1.7

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

3,318
mimir-openshift-experimentalgrafana2.1.02 of 4See more

mimir-openshift-experimental grafana 2.1.0

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0

Open the chart page →

17,759
pyroscope-monitoringgrafana0.1.11 of 6See more

pyroscope-monitoring grafana 0.1.1

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

8,188
prometheusgrafana-uxadax26.0.16 of 6See more

prometheus grafana-uxadax 26.0.1

6 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/oauth2@v0.22.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

5,304
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,510
fasttrackmlgresearch0.1.01 of 1See more

fasttrackml gresearch 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

1,391
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.18.16a41efe02a041
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

14,312
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

2,590
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,175
docker-authhalkeye0.1.11 of 1See more

docker-auth halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,374
cert-manager-webhook-arvanhbahadorzadeh0.1.11 of 1See more

cert-manager-webhook-arvan hbahadorzadeh 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,022
kubernetes-event-exporterhbahadorzadeh0.1.01 of 1See more

kubernetes-event-exporter hbahadorzadeh 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,630
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
supabase/gotrue:v2.91.07174d551d720
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

24,995
helm-airportshelm-airports0.1.01 of 7See more

helm-airports helm-airports 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

12,696
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

4,547
helm-airportshelm-airports-dan0.1.01 of 7See more

helm-airports helm-airports-dan 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

5,573
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

4,547
logging-stackhelm-charts-alexis-carbillet0.1.05 of 9See more

logging-stack helm-charts-alexis-carbillet 0.1.0

5 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
grafana/grafana:11.1.0079600c9517b
golang.org/x/oauth2@v0.20.0
0.27.0
grafana/loki:2.6.11ee60f980950
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
grafana/loki:2.8.2b1da1d23037e
golang.org/x/oauth2@v0.4.0
0.27.0
grafana/loki-canary:2.6.1ab2a2569307b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

12,650
monitoring-stackhelm-charts-alexis-carbillet0.1.07 of 11See more

monitoring-stack helm-charts-alexis-carbillet 0.1.0

7 of the 11 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/oauth2@v0.23.0
0.27.0
prom/prometheus:v2.48.1a67e5e402ff5
golang.org/x/oauth2@v0.13.0
0.27.0
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/oauth2@v0.8.0
0.27.0
quay.io/prometheus/node-exporter:v1.7.04cb2b9019f17
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/oauth2@v0.8.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

9,460
aws-ebs-csi-driverhelm-charts-nr2.17.44 of 6See more

aws-ebs-csi-driver helm-charts-nr 2.17.4

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/oauth2@v0.1.0
0.27.0
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/oauth2@v0.2.0
0.27.0
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

6,483
cortex-gatewayhelm-charts-nr0.1.91 of 1See more

cortex-gateway helm-charts-nr 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0

Open the chart page →

2,234
dregsyhelm-charts-nr0.1.51 of 1See more

dregsy helm-charts-nr 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/oauth2@v0.0.0-20201109201403-9fd604954f58
0.27.0

Open the chart page →

2,969
k8s-cloudwatch-adapterhelm-charts-nr0.2.21 of 1See more

k8s-cloudwatch-adapter helm-charts-nr 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,468
k8s-event-loggerhelm-charts-nr1.1.91 of 1See more

k8s-event-logger helm-charts-nr 1.1.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
maxrocketinternet/k8s-event-logger:2.111224534789d
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0

Open the chart page →

864
kube-benchhelm-charts-nr0.1.171 of 1See more

kube-bench helm-charts-nr 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,623
labelsmanager-controllerhelm-charts-nr1.0.41 of 1See more

labelsmanager-controller helm-charts-nr 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,305
node-local-dnshelm-charts-nr2.1.41 of 1See more

node-local-dns helm-charts-nr 2.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

2,222
node-problem-detectorhelm-charts-nr2.3.171 of 1See more

node-problem-detector helm-charts-nr 2.3.17

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

2,434
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/oauth2@v0.0.0-20181106182150-f42d05182288
0.27.0

Open the chart page →

7,984
answerhelmforgeVerified publisher1.5.21 of 1See more

answer helmforge 1.5.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apache/answer:2.0.2a0d71b0e30a5
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

556
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

25,017
printserverhmediadeVerified publisher1.0.22 of 4See more

printserver hmediade 1.0.2

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/oauth2@v0.12.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

10,839
imageproxyhmphuVerified publisher0.1.11 of 1See more

imageproxy hmphu 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0

Open the chart page →

2,140
cert-managerhomeenterpriseinc1.10.13 of 3See more

cert-manager homeenterpriseinc 1.10.1

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.10.164121721c665
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0

Open the chart page →

4,720
hammerspace-csihscsi1.2.83 of 6See more

hammerspace-csi hscsi 1.2.8

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/oauth2@v0.25.0
0.27.0
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

4,441
cac-systemhuangchengwu-helm-chart0.1.07 of 9See more

cac-system huangchengwu-helm-chart 0.1.0

7 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
golang.org/x/oauth2@v0.6.0
0.27.0
quay.io/jetstack/cert-manager-cainjector:v1.12.0e0a5b06b231c
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.12.0ec4306b243d9
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

11,186
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

16,401
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

20,650
tdenginehuangchengwu-helm-chart3.0.21 of 1See more

tdengine huangchengwu-helm-chart 3.0.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tdengine/tdengine:3.0.2.24140a4021ddb
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0

Open the chart page →

3,747
stoloniamalryz0.10.01 of 2See more

stolon iamalryz 0.10.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,045
monitoring-stackict-platformVerified publisher0.4.02 of 13See more

monitoring-stack ict-platform 0.4.0

2 of the 13 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
golang.org/x/oauth2@v0.23.0
0.27.0
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

9,573
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

8,967
ikigaiikigai-chartVerified publisher0.0.93 of 58See more

ikigai ikigai-chart 0.0.9

3 of the 58 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kuberay/operator:v1.0.04e6ac8a3a2c4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
rabbitmqoperator/cluster-operator:2.6.08651dd3cec51
golang.org/x/oauth2@v0.8.0
0.27.0
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

37,671
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,165
ilum-jupyterhubilumVerified publisher4.3.11 of 6See more

ilum-jupyterhub ilum 4.3.1

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,835
ilum-otel-collectorilumVerified publisher0.1.01 of 1See more

ilum-otel-collector ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.113.05ac3e0ba2b0b
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,384
kore-boardimprowisedVerified publisher0.5.83 of 4See more

kore-board improwised 0.5.8

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.backend:v0.5.5455f6e7a26fd
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
ghcr.io/kore3lab/kore-board.metrics-scraper:v0.5.547f88b18fb7c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

16,212
fpga-cloudinaccelVerified publisher1.2.23 of 3See more

fpga-cloud inaccel 1.2.2

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
inaccel/cloud-init:latesta5d3d0af05c1
golang.org/x/oauth2@v0.15.0
0.27.0
inaccel/device-selector:latest44b4f274f40b
golang.org/x/oauth2@v0.14.0
0.27.0
inaccel/kubevirt-hack:latestbdfd61803a70
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

3,152
fpga-operatorinaccelVerified publisher2.8.21 of 7See more

fpga-operator inaccel 2.8.2

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
inaccel/reef:latestc967218739f3
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

5,759

Container images carrying it

1,999 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/oauth2@v0.6.0
0.27.0
3
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/oauth2@v0.22.0
0.27.0
3
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/oauth2@v0.18.0
0.27.0
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/oauth2@v0.8.0
0.27.0
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/oauth2@v0.18.0
0.27.0
3
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/oauth2@v0.21.0
0.27.0
3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/oauth2@v0.4.0
0.27.0
3
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/oauth2@v0.25.0
0.27.0
3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
3
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/oauth2@v0.25.0
0.27.0
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
3
alazidis/kube-netlag:1.1.00e8c84152201
golang.org/x/oauth2@v0.24.0
0.27.0
2
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/oauth2@v0.23.0
0.27.0
2
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
apecloud/apecloud-mcp:0.1.094041b080510
golang.org/x/oauth2@v0.25.0
0.27.0
2
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/oauth2@v0.15.0
0.27.0
2
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
2
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/oauth2@v0.3.0
0.27.0
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
datawire/aes:1.14.48588eafe6862
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/oauth2@v0.22.0
0.27.0
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/oauth2@v0.10.0
0.27.0
2
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/oauth2@v0.19.0
0.27.0
2
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/oauth2@v0.7.0
0.27.0
2
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/udm:v3.4.32f68df062a50
golang.org/x/oauth2@v0.15.0
0.27.0
2
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/oauth2@v0.8.0
0.27.0
2
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
2
governify/dashboard:lateste83a17ba5038
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0
2
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
2
grafana/grafana:9.2.4057896e23443
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.