StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,633
of 17,792 indexed, latest versions
Container images
2,030
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,633 of 17,792 indexed charts deploy, on 2,030 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,030
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,633 by stars
ChartLatestAffected imagesRadar Score
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,218
agentkube-operatoragentkube-operator0.3.01 of 1See more

agentkube-operator agentkube-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,723
mt-channel-brokerahhhhVerified publisher0.1.03 of 3See more

mt-channel-broker ahhhh 0.1.0

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/filterdigest-pinnedd675f211a40f
golang.org/x/oauth2@v0.22.0
0.27.0
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/ingressdigest-pinnedec4b544499ba
golang.org/x/oauth2@v0.22.0
0.27.0
gcr.io/knative-releases/knative.dev/eventing/cmd/mtchannel_brokerdigest-pinned395f4ff1bd34
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

2,628
net-istioahhhhVerified publisher0.1.12 of 2See more

net-istio ahhhh 0.1.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinnede70bc675f977
golang.org/x/oauth2@v0.22.0
0.27.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned7d76a6d42d13
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

1,128
net-kourierahhhhVerified publisher0.18.11 of 1See more

net-kourier ahhhh 0.18.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourierdigest-pinned15a601147ef4
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

515
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

4,974
airbyteairbyte-v2Verified publisher2.3.02 of 10See more

airbyte airbyte-v2 2.3.0

2 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
airbyte/minio:RELEASE.2023-11-20T22-40-07Zfdae972eaf0e
golang.org/x/oauth2@v0.13.0
0.27.0
temporalio/auto-setup:1.27.2b44cbfeb43db
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

11,785
airports-kafkaairports-kafka0.1.01 of 2See more

airports-kafka airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

4,558
akriakri0.12.551 of 3See more

akri akri 0.12.55

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

1,545
aktoakto0.2.01 of 7See more

akto akto 0.2.0

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

13,737
akto-hybrid-redactakto1.44.61 of 5See more

akto-hybrid-redact akto 1.44.6

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

4,101
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

6,600
akto-mini-testing-kafkaakto1.42.11 of 5See more

akto-mini-testing-kafka akto 1.42.1

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

6,406
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

11,296
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

4,865
kpubberalekcVerified publisher0.0.41 of 1See more

kpubber alekc 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,228
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,116
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

564
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

564
katalogalpineworks0.1.21 of 5See more

katalog alpineworks 0.1.2

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

4,542
katalog-agentalpineworks0.1.21 of 1See more

katalog-agent alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

582
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
golang.org/x/oauth2@v0.10.0
0.27.0
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/oauth2@v0.5.0
0.27.0
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/oauth2@v0.8.0
0.27.0
daprio/operator:1.11.2c584428aa12d
golang.org/x/oauth2@v0.8.0
0.27.0
daprio/placement:1.11.2d8e1446da996
golang.org/x/oauth2@v0.8.0
0.27.0
daprio/sentry:1.11.21f507c1a181b
golang.org/x/oauth2@v0.8.0
0.27.0
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/oauth2@v0.11.0
0.27.0
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/oauth2@v0.11.0
0.27.0

Open the chart page →

28,342
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

1,326
dnsmadeeasy-webhookangelnu6.0.71 of 1See more

dnsmadeeasy-webhook angelnu 6.0.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/angelnu/dnsmadeeasy-webhook:v1.9.0a5ca158b1f02
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

810
maddyangelnu5.0.01 of 1See more

maddy angelnu 5.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

774
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,495
ddosifyanteonVerified publisher1.7.53 of 13See more

ddosify anteon 1.7.5

3 of the 13 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/oauth2@v0.10.0
0.27.0
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
prom/prometheus:v2.37.98176adea328e
golang.org/x/oauth2@v0.0.0-20220628200809-02e64fa58f26
0.27.0

Open the chart page →

26,070
antmediaantmediaVerified publisher3.1.02 of 4See more

antmedia antmedia 3.1.0

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,631
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,323
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,731
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

2,962
app-mobilityappmo0.1.03 of 5See more

app-mobility appmo 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
golang.org/x/oauth2@v0.0.0-20220622183110-fd043fe589d2
0.27.0
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
velero/velero:v1.8.18d784580931c
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

12,542
auditorappscodeVerified publisher2023.10.11 of 1See more

auditor appscode 2023.10.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,680
capa-vpc-peering-operatorappscodeVerified publisher2023.12.111 of 1See more

capa-vpc-peering-operator appscode 2023.12.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
golang.org/x/oauth2@v0.11.0
0.27.0

Open the chart page →

1,433
capi-ops-managerappscodeVerified publisher2024.8.142 of 2See more

capi-ops-manager appscode 2024.8.14

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
golang.org/x/oauth2@v0.22.0
0.27.0
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,430
cluster-proxyappscodeVerified publisher2024.2.251 of 1See more

cluster-proxy appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-proxy:latest27a5c64b7ea8
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,126
cluster-proxy-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-proxy-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-proxy:v0.10.1a7fce69e171c
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,472
docker-machine-operatorappscodeVerified publisher2024.7.91 of 1See more

docker-machine-operator appscode 2024.7.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

2,227
fluxcd-addon-managerappscodeVerified publisher2024.2.251 of 1See more

fluxcd-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/fluxcd-addon:v0.0.23acba3df8827
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,311
gateway-converterappscodeVerified publisher2024.8.301 of 1See more

gateway-converter appscode 2024.8.30

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway-converter:v0.0.1b92123805584
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,275
gh-ci-webhookappscodeVerified publisher2026.9.111 of 1See more

gh-ci-webhook appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/gh-ci-webhook:v0.0.2036ce246d884e
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,248
grafanaappscodeVerified publisher2026.9.111 of 1See more

grafana appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana:v2025.2.367d18880448c
golang.org/x/oauth2@v0.0.0-20210113205817-d3ed898aa8a3
0.27.0

Open the chart page →

2,340
inbox-agentappscodeVerified publisher2026.6.21 of 2See more

inbox-agent appscode 2026.6.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.15.0d8cc6ffb9819
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,129
kube-auth-managerappscodeVerified publisher2023.11.141 of 1See more

kube-auth-manager appscode 2023.11.14

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,946
kube-auth-proxyappscodeVerified publisher2023.11.141 of 1See more

kube-auth-proxy appscode 2023.11.14

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,946
kubedb-communityappscodeVerified publisher0.24.21 of 2See more

kubedb-community appscode 0.24.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubedb/operator:v0.24.01a06ff0bda52
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,557
kubedb-enterpriseappscodeVerified publisher0.11.21 of 2See more

kubedb-enterprise appscode 0.11.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubedb/kubedb-enterprise:v0.11.05829bcedcb0d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,582
kubedb-oneappscodeVerified publisher2023.12.289 of 10See more

kubedb-one appscode 2023.12.28

9 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
ghcr.io/kubedb/kubedb-autoscaler:v0.25.0df6b11907d33
golang.org/x/oauth2@v0.13.0
0.27.0
ghcr.io/kubedb/kubedb-dashboard:v0.16.07bfe1c07bd9b
golang.org/x/oauth2@v0.13.0
0.27.0
ghcr.io/kubedb/kubedb-ops-manager:v0.27.1ec36422b09af
golang.org/x/oauth2@v0.13.0
0.27.0
ghcr.io/kubedb/kubedb-provisioner:v0.40.242574f512837
golang.org/x/oauth2@v0.13.0
0.27.0
ghcr.io/kubedb/kubedb-schema-manager:v0.16.09518de37eed5
golang.org/x/oauth2@v0.13.0
0.27.0
ghcr.io/kubedb/kubedb-webhook-server:v0.16.2e24894e32cbc
golang.org/x/oauth2@v0.13.0
0.27.0
ghcr.io/stashed/stash-crd-installer:v0.32.0c6f2a844b5dd
golang.org/x/oauth2@v0.5.0
0.27.0
ghcr.io/stashed/stash-enterprise:v0.32.0e9bde36e34b7
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

15,273
kubedb-provider-awsappscodeVerified publisher2026.7.101 of 1See more

kubedb-provider-aws appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-aws:v0.27.049b1c312e342
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

2,534
kubedb-provider-azureappscodeVerified publisher2026.7.101 of 1See more

kubedb-provider-azure appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

2,712

Container images carrying it

2,030 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/oauth2@v0.19.0
0.27.0
1
ghcr.io/kyverno/policy-reporter:2.14.1e74c6bf33d1b
golang.org/x/oauth2@v0.6.0
0.27.0
1
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/oauth2@v0.19.0
0.27.0
1
ghcr.io/lavanet/lava/lavap:v2.5.089028adefcff
golang.org/x/oauth2@v0.16.0
0.27.0
1
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/oauth2@v0.4.0
0.27.0
1
ghcr.io/loft-sh/central-hostpath-mapper:0.2.9fa6dba122171
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/oauth2@v0.9.0
0.27.0
1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/oauth2@v0.17.0
0.27.0
1
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
golang.org/x/oauth2@v0.20.0
0.27.0
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
golang.org/x/oauth2@v0.11.0
0.27.0
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
golang.org/x/oauth2@v0.3.0
0.27.0
1
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
golang.org/x/oauth2@v0.11.0
0.27.0
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/middleware-labs/mw-lang-detector:0.1.2a4776aa2a56b
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
golang.org/x/oauth2@v0.25.0
0.27.0
1
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/oauth2@v0.5.0
0.27.0
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
golang.org/x/oauth2@v0.20.0
0.27.0
1
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/muhmmadayan/fake-network-operator:0.1.03806b1fd4a4b
golang.org/x/oauth2@v0.22.0
0.27.0
1
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/nefelim4ag/k8s-ondemand-proxy:0.0.2078b25d48cf7
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.