StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,634
of 17,787 indexed, latest versions
Container images
2,031
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,634 of 17,787 indexed charts deploy, on 2,031 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,031
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,634 by stars
ChartLatestAffected imagesRadar Score
medewerkercatalogusmedewerkercatalogus1.0.01 of 3See more

medewerkercatalogus medewerkercatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,327
crdsmedia-streaming-meshVerified publisher0.0.11 of 2See more

crds media-streaming-mesh 0.0.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ciscolabs/msm-nc:0710202336d02faad958
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

3,707
ingressmedia-streaming-meshVerified publisher0.1.82 of 2See more

ingress media-streaming-mesh 0.1.8

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
golang.org/x/oauth2@v0.5.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,301
msmmedia-streaming-meshVerified publisher0.1.174 of 6See more

msm media-streaming-mesh 0.1.17

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
golang.org/x/oauth2@v0.21.0
0.27.0
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

11,478
mediawiki-backupmediawiki-backupVerified publisher0.2.11 of 1See more

mediawiki-backup mediawiki-backup 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,919
memo-componentmemo-component1.0.01 of 3See more

memo-component memo-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/memo-component-php:latestef77f4c089a1
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,510
dex-k8s-authenticatormesosphere1.4.31 of 1See more

dex-k8s-authenticator mesosphere 1.4.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mesosphere/dex-k8s-authenticator:v1.4.1-d2iqf3d9982cc2fd
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,019
flaggermesosphere0.21.01 of 2See more

flagger mesosphere 0.21.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
weaveworks/flagger:0.19.0a9c2e9df4227
golang.org/x/oauth2@v0.0.0-20190402181905-9f3314589c9a
0.27.0

Open the chart page →

6,048
gatekeepermesosphere0.6.111 of 2See more

gatekeeper mesosphere 0.6.11

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,034
istiomesosphere1.25.11 of 2See more

istio mesosphere 1.25.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

4,786
kafka-operatormesosphere0.20.21 of 2See more

kafka-operator mesosphere 0.20.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/kafka-operator:v0.20.2e341aefa9a90
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

1,884
kubeaddons-catalogmesosphere0.1.161 of 2See more

kubeaddons-catalog mesosphere 0.1.16

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

12,049
kubefedmesosphere0.5.21 of 1See more

kubefed mesosphere 0.5.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mesosphere/kubefed:proxyurl4fd8889195fe
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,144
kube-oidc-proxymesosphere0.3.41 of 1See more

kube-oidc-proxy mesosphere 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

3,144
kube-prometheus-stackmesosphere87.16.01 of 7See more

kube-prometheus-stack mesosphere 87.16.0

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

6,763
kudomesosphere0.1.41 of 1See more

kudo mesosphere 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kudobuilder/controller:v0.9.069072d979708
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

5,688
local-path-provisionermesosphere0.0.221 of 1See more

local-path-provisioner mesosphere 0.0.22

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.22e34c88ae0aff
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,317
nfs-server-provisionermesosphere0.6.11 of 1See more

nfs-server-provisioner mesosphere 0.6.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,806
prometheus-operatormesosphere12.11.132 of 8See more

prometheus-operator mesosphere 12.11.13

2 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0

Open the chart page →

11,690
traefik2mesosphere9.18.01 of 1See more

traefik2 mesosphere 9.18.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/traefik:2.4.8eda951fd29a8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,341
azuredisk-csi-drivermesosphere-stable0.8.14 of 6See more

azuredisk-csi-driver mesosphere-stable 0.8.1

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
mcr.microsoft.com/oss/kubernetes-csi/csi-provisioner:v1.6.1667b1b1ea1e4
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.1.07997e0f236bc
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0

Open the chart page →

14,067
cert-manager-setupmesosphere-stable0.2.104 of 5See more

cert-manager-setup mesosphere-stable 0.2.10

4 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/oauth2@v0.4.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/oauth2@v0.4.0
0.27.0
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/oauth2@v0.4.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

7,179
dexmesosphere-stable2.14.13 of 5See more

dex mesosphere-stable 2.14.1

3 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/oauth2@v0.10.0
0.27.0
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
golang.org/x/oauth2@v0.9.0
0.27.0
mesosphere/dex-controller:v0.16.11b2dd9c0b0fc
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

18,583
gatekeepermesosphere-stable0.6.111 of 2See more

gatekeeper mesosphere-stable 0.6.11

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,034
istiomesosphere-stable1.25.11 of 2See more

istio mesosphere-stable 1.25.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

4,786
kafka-operatormesosphere-stable0.25.11 of 2See more

kafka-operator mesosphere-stable 0.25.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

1,241
knativemesosphere-stable1.10.87 of 7See more

knative mesosphere-stable 1.10.8

7 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.10.2c2994c2b6c2c
golang.org/x/oauth2@v0.1.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.10.28319aa662b49
golang.org/x/oauth2@v0.1.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpa:v1.10.2eb612b929eaa
golang.org/x/oauth2@v0.1.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
golang.org/x/oauth2@v0.1.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.10.2f66c41ad7a73
golang.org/x/oauth2@v0.1.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.10.27368aaddf2be
golang.org/x/oauth2@v0.1.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.10.24305209ce498
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

7,479
kommandermesosphere-stable0.39.216 of 29See more

kommander mesosphere-stable 0.39.2

16 of the 29 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:6.6.0052147d7e0ec
golang.org/x/oauth2@v0.0.0-20190319182350-c85d3e98c914
0.27.0
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
mesosphere/kubeaddons-addon-initializer:v0.2.8c10011f866f2
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
prom/prometheus:v2.19.2cd134bd4fca0
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
thanosio/thanos:v0.19.088276fcd1491
golang.org/x/oauth2@v0.0.0-20210210192628-66670185b0cd
0.27.0
thanosio/thanos:v0.15.0b12d5c31bf5a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
golang.org/x/oauth2@v0.0.0-20190402181905-9f3314589c9a
0.27.0
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/thanos/thanos:v0.17.1e362f02ed304
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0

Open the chart page →

68,330
kube-prometheus-stackmesosphere-stable75.9.11 of 7See more

kube-prometheus-stack mesosphere-stable 75.9.1

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

9,543
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.2.09f863160127b
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,027
veleromesosphere-stable3.2.51 of 1See more

velero mesosphere-stable 3.2.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,871
cortexmetakube0.6.01 of 2See more

cortex metakube 0.6.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0

Open the chart page →

4,107
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

8,940
wg-access-servermglants0.4.71 of 1See more

wg-access-server mglants 0.4.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,745
kube-agent-chartmiddleware-labsVerified publisher0.1.21 of 1See more

kube-agent-chart middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

1,799
middleware-odigosmiddleware-labsVerified publisher0.2.414 of 6See more

middleware-odigos middleware-labs 0.2.41

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

8,370
middleware-visionmiddleware-labsVerified publisher0.2.654 of 6See more

middleware-vision middleware-labs 0.2.65

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

8,361
mw-autoinstrumentationmiddleware-labsVerified publisher1.2.63 of 6See more

mw-autoinstrumentation middleware-labs 1.2.6

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
golang.org/x/oauth2@v0.21.0
0.27.0
ghcr.io/middleware-labs/mw-lang-detector:0.1.2a4776aa2a56b
golang.org/x/oauth2@v0.21.0
0.27.0
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

3,714
mw-kube-agentmiddleware-labsVerified publisher0.1.21 of 1See more

mw-kube-agent middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
golang.org/x/oauth2@v0.11.0
0.27.0

Open the chart page →

1,594
argocd-extra-app-info-exportermikejohVerified publisher0.1.121 of 1See more

argocd-extra-app-info-exporter mikejoh 0.1.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,334
local-path-provisionermikejohVerified publisher0.0.291 of 1See more

local-path-provisioner mikejoh 0.0.29

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.299bebefa0b908
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,300
miniomilvus-helm8.0.201 of 1See more

minio milvus-helm 8.0.20

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2024-05-28T17-19-04Z391d1d45fdbe
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

1,537
pulsarv2milvus-helm2.7.82 of 4See more

pulsarv2 milvus-helm 2.7.8

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

15,855
mimirmimir0.1.101 of 1See more

mimir mimir 0.1.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/heimops/mimir-operator:latest4e1a3ef1fe82
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

382
minio-operatorminio-operator4.3.71 of 2See more

minio-operator minio-operator 4.3.7

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

6,085
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

10,639
standard-application-stackmintel11.4.11 of 12See more

standard-application-stack mintel 11.4.1

1 of the 12 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

10,515
jupyterhubmizzoukube0.0.1-set.by.chartpress1 of 7See more

jupyterhub mizzoukube 0.0.1-set.by.chartpress

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,883
cert-manager-webhook-duckdnsmmontesVerified publisher1.2.31 of 1See more

cert-manager-webhook-duckdns mmontes 1.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,847
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
golang.org/x/oauth2@v0.0.0-20190115181402-5dab4167f31c
0.27.0

Open the chart page →

7,775

Container images carrying it

2,031 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/oauth2@v0.23.0
0.27.0
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/oauth2@v0.6.0
0.27.0
3
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/oauth2@v0.22.0
0.27.0
3
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/oauth2@v0.18.0
0.27.0
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/oauth2@v0.8.0
0.27.0
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/oauth2@v0.18.0
0.27.0
3
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/oauth2@v0.21.0
0.27.0
3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/oauth2@v0.4.0
0.27.0
3
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/oauth2@v0.25.0
0.27.0
3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
3
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/oauth2@v0.25.0
0.27.0
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
3
alazidis/kube-netlag:1.1.00e8c84152201
golang.org/x/oauth2@v0.24.0
0.27.0
2
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/oauth2@v0.23.0
0.27.0
2
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
apecloud/apecloud-mcp:0.1.094041b080510
golang.org/x/oauth2@v0.25.0
0.27.0
2
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/oauth2@v0.15.0
0.27.0
2
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
2
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/oauth2@v0.3.0
0.27.0
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
datawire/aes:1.14.48588eafe6862
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/oauth2@v0.22.0
0.27.0
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/oauth2@v0.10.0
0.27.0
2
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/oauth2@v0.19.0
0.27.0
2
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/oauth2@v0.7.0
0.27.0
2
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
2
free5gc/udm:v3.4.32f68df062a50
golang.org/x/oauth2@v0.15.0
0.27.0
2
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/oauth2@v0.8.0
0.27.0
2
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
2
governify/dashboard:lateste83a17ba5038
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0
2
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.