StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,634
of 17,787 indexed, latest versions
Container images
2,031
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,634 of 17,787 indexed charts deploy, on 2,031 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,031
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,634 by stars
ChartLatestAffected imagesRadar Score
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

8,534
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

26,371
cachelavaOfficialVerified publisher1.1.11 of 1See more

cache lava 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/lavanet/lava/lavap:v2.5.089028adefcff
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,378
metallblectures-k8sinfra0.10.22 of 2See more

metallb lectures-k8sinfra 0.10.2

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.10.221164241c045
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/metallb/speaker:v0.10.258cb99053bb3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

5,406
prometheuslectures-k8sinfra15.8.54 of 6See more

prometheus lectures-k8sinfra 15.8.5

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
golang.org/x/oauth2@v0.0.0-20220628200809-02e64fa58f26
0.27.0

Open the chart page →

9,092
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

3,191
prometheusleechistest11.6.01 of 6See more

prometheus leechistest 11.6.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

8,484
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
golang.org/x/oauth2@v0.0.0-20220718184931-c8730f7fcb92
0.27.0

Open the chart page →

4,271
minioleprechaun-charts0.1.61 of 1See more

minio leprechaun-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-01-20T14-49-07Z-cpuv114b7076ca85a
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,312
kltlifecycle-toolkitOfficialVerified publisher0.2.64 of 4See more

klt lifecycle-toolkit 0.2.6

4 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/keptn/certificate-operator:v1.1.08fdd311a6d33
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
ghcr.io/keptn/lifecycle-operator:v0.8.2487bfc37c4b4
golang.org/x/oauth2@v0.8.0
0.27.0
ghcr.io/keptn/metrics-operator:v0.8.2acf22310e9dd
golang.org/x/oauth2@v0.10.0
0.27.0
ghcr.io/keptn/scheduler:v0.8.20f7d277bb2b2
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

4,659
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,456
lightsteplightstep-microsat2.0.211 of 1See more

lightstep lightstep-microsat 2.0.21

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,116
linkerd-preview-vizlinkerd-buoyantVerified publisher25.4.34 of 5See more

linkerd-preview-viz linkerd-buoyant 25.4.3

4 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/metrics-api:preview-25.4.32cef2a3f97da
golang.org/x/oauth2@v0.25.0
0.27.0
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/buoyantio/tap:preview-25.4.3e02a8bd9e2c3
golang.org/x/oauth2@v0.25.0
0.27.0
ghcr.io/buoyantio/web:preview-25.4.33ee1b62aa111
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

3,420
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

2,129
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/session-manager-server:1.9.0f24ecd37fbaa
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

12,034
otlp-gatewayloafoe0.0.21 of 2See more

otlp-gateway loafoe 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

2,155
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

4,904
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

2,101
tempo-distributedloafoe1.20.11 of 2See more

tempo-distributed loafoe 1.20.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

2,020
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,510
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

7,516
central-hostpath-mapperloftVerified publisher0.2.91 of 1See more

central-hostpath-mapper loft 0.2.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/central-hostpath-mapper:0.2.9fa6dba122171
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

917
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,225
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

9,880
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,086
loft-agentloftVerified publisher3.2.41 of 1See more

loft-agent loft 3.2.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

2,444
loft-direct-cluster-endpointloftVerified publisher1.14.01 of 1See more

loft-direct-cluster-endpoint loft 1.14.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,112
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/oauth2@v0.17.0
0.27.0

Open the chart page →

3,225
vcluster-proloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

5,085
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.101 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

5,936
vcluster-pro-k0sloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro-k0s loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
golang.org/x/oauth2@v0.3.0
0.27.0
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

5,770
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.103 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/oauth2@v0.8.0
0.27.0
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

8,206
virtualclusterloftVerified publisher0.0.281 of 2See more

virtualcluster loft 0.0.28

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,986
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,507
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,492
nightingalelogic3579Verified publisher0.3.11 of 6See more

nightingale logic3579 0.3.1

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

9,021
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,498
apica-ascentlogiqai2.0.42 of 19See more

apica-ascent logiqai 2.0.4

2 of the 19 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
golang.org/x/oauth2@v0.16.0
0.27.0
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0

Open the chart page →

23,255
loxilbloxilbVerified publisher0.1.01 of 2See more

loxilb loxilb 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

4,502
lsdisklsdiskVerified publisher2.0.72 of 4See more

lsdisk lsdisk 2.0.7

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-provisioner:v5.0.27b9cdb5830d0
golang.org/x/oauth2@v0.20.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

5,032
chronograflsst-sqre1.3.51 of 1See more

chronograf lsst-sqre 1.3.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0

Open the chart page →

2,342
sasquatchlsst-sqre0.1.132 of 6See more

sasquatch lsst-sqre 0.1.13

2 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/kapacitor:1.6.37232f6388a4d
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0

Open the chart page →

9,332
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

6,623
telegraf-dslsst-sqre1.0.231 of 1See more

telegraf-ds lsst-sqre 1.0.23

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,764
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
golang.org/x/oauth2@v0.11.0
0.27.0

Open the chart page →

9,786
magistralamagistrala-devopsVerified publisher0.16.27 of 42See more

magistrala magistrala-devops 0.16.2

7 of the 42 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.31cc420186664
golang.org/x/oauth2@v0.18.0
0.27.0
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

24,488
kruisematrixone-operatorVerified publisher1.8.32 of 2See more

kruise matrixone-operator 1.8.3

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
openkruise/kruise-helm-hook:v0.1.0edc7cf9428fd
golang.org/x/oauth2@v0.17.0
0.27.0
openkruise/kruise-manager:v1.8.30482722b4e56
golang.org/x/oauth2@v0.17.0
0.27.0

Open the chart page →

1,767
mattermost-calls-offloadermattermostVerified publisher0.2.11 of 1See more

mattermost-calls-offloader mattermost 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mattermost/calls-offloader:v0.9.0b440b282599e
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,414
mattermost-push-proxymattermostVerified publisher0.14.31 of 1See more

mattermost-push-proxy mattermost 0.14.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mattermost/mattermost-push-proxy:6.3.045c53061c74e
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

890
mayastormayastorVerified publisher2.12.18 of 31See more

mayastor mayastor 2.12.1

8 of the 31 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:3.4.258a6c186ce78
golang.org/x/oauth2@v0.25.0
0.27.0
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/oauth2@v0.25.0
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/oauth2@v0.25.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/oauth2@v0.25.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/oauth2@v0.25.0
0.27.0
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

21,178

Container images carrying it

2,031 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/oauth2@v0.23.0
0.27.0
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/oauth2@v0.6.0
0.27.0
3
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/oauth2@v0.22.0
0.27.0
3
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/oauth2@v0.18.0
0.27.0
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/oauth2@v0.8.0
0.27.0
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/oauth2@v0.18.0
0.27.0
3
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/oauth2@v0.21.0
0.27.0
3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/oauth2@v0.4.0
0.27.0
3
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/oauth2@v0.25.0
0.27.0
3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
3
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/oauth2@v0.25.0
0.27.0
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
3
alazidis/kube-netlag:1.1.00e8c84152201
golang.org/x/oauth2@v0.24.0
0.27.0
2
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/oauth2@v0.23.0
0.27.0
2
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
apecloud/apecloud-mcp:0.1.094041b080510
golang.org/x/oauth2@v0.25.0
0.27.0
2
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/oauth2@v0.15.0
0.27.0
2
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
2
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/oauth2@v0.3.0
0.27.0
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
datawire/aes:1.14.48588eafe6862
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/oauth2@v0.22.0
0.27.0
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/oauth2@v0.10.0
0.27.0
2
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/oauth2@v0.19.0
0.27.0
2
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/oauth2@v0.7.0
0.27.0
2
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/udm:v3.4.32f68df062a50
golang.org/x/oauth2@v0.15.0
0.27.0
2
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/oauth2@v0.8.0
0.27.0
2
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
2
governify/dashboard:lateste83a17ba5038
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0
2
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.