StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,633
of 17,803 indexed, latest versions
Container images
2,030
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,633 of 17,803 indexed charts deploy, on 2,030 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,030
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,633 by stars
ChartLatestAffected imagesRadar Score
alertmanagersignoz0.5.21 of 1See more

alertmanager signoz 0.5.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
signoz/alertmanager:0.5.07bc7de2e33c2
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

2,182
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

2,870
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
golang.org/x/oauth2@v0.14.0
0.27.0

Open the chart page →

2,347
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,381
olmsikalabs0.3.01 of 2See more

olm sikalabs 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned40d0363f4aa6
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

1,162
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,502
keydbsinextraVerified publisher0.31.01 of 1See more

keydb sinextra 0.31.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

2,172
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
golang.org/x/oauth2@v0.11.0
0.27.0

Open the chart page →

2,448
mimirskyloud-helm-chartsVerified publisher5.5.13 of 5See more

mimir skyloud-helm-charts 5.5.1

3 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/mimir:r292-5f018727476e456c738
golang.org/x/oauth2@v0.19.0
0.27.0
grafana/rollout-operator:v0.14.03409edfb45c7
golang.org/x/oauth2@v0.17.0
0.27.0
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

10,819
tailscale-operatorskyloud-helm-chartsVerified publisher1.70.31 of 1See more

tailscale-operator skyloud-helm-charts 1.70.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tailscale/k8s-operator:v1.70.08edd06cf5bac
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,045
skypilot-prometheus-serverskypilotVerified publisher0.11.11 of 3See more

skypilot-prometheus-server skypilot 0.11.1

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.15.0db384bf43222
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

2,360
config-connector-templaterslamdev0.0.51 of 1See more

config-connector-templater slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
slamdev/config-connector-templater:0.0.3a234541c9fa8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,110
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
golang.org/x/oauth2@v0.0.0-20201203001011-0b49973bad19
0.27.0

Open the chart page →

9,261
gke-preemptible-notifierslamdev0.0.61 of 1See more

gke-preemptible-notifier slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,861
octavia-ingress-controllerslamdev0.0.71 of 1See more

octavia-ingress-controller slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,761
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
golang.org/x/oauth2@v0.0.0-20181106182150-f42d05182288
0.27.0

Open the chart page →

8,732
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

3,471
cost-analyzersoftonic2.5.53 of 6See more

cost-analyzer softonic 2.5.5

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.5.28b37a2f028f1
golang.org/x/oauth2@v0.25.0
0.27.0
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
golang.org/x/oauth2@v0.22.0
0.27.0
quay.io/prometheus/prometheus:v3.2.16927e0919a14
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

8,166
csi-gcs-softonic-factorysoftonic0.9.31 of 4See more

csi-gcs-softonic-factory softonic 0.9.3

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ofekmeister/csi-gcs:v0.9.030d70fa9211b
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

1,849
harborsoftonic1.13.03 of 8See more

harbor softonic 1.13.0

3 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
golang.org/x/oauth2@v0.5.0
0.27.0
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/oauth2@v0.5.0
0.27.0
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

7,708
kyvernosoftonic3.5.21 of 7See more

kyverno softonic 3.5.2

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.32.73c5268158974
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,021
pod-defaultersoftonic0.1.31 of 1See more

pod-defaulter softonic 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
softonic/pod-defaulter:0.1.072017aed5902
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,562
policy-reportersoftonic2.18.21 of 1See more

policy-reporter softonic 2.18.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kyverno/policy-reporter:2.14.1e74c6bf33d1b
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,045
preemptible-killersoftonic1.2.61 of 1See more

preemptible-killer softonic 1.2.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
softonic/preemptible-killer:1.2.6-294b87f1fb362
golang.org/x/oauth2@v0.0.0-20170807180024-9a379c6b3e95
0.27.0

Open the chart page →

2,339
rate-limit-operatorsoftonic1.1.01 of 2See more

rate-limit-operator softonic 1.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
softonic/rate-limit-operator:0.1.1910f6de37763
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,220
rclonesoftonic2.1.01 of 1See more

rclone softonic 2.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rclone/rclone:1.6874c51b8817e5
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,680
redis-operatorsoftonic0.18.01 of 1See more

redis-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/ot-container-kit/redis-operator/redis-operator:v0.18.090bfeb2e0d71
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

551
sealed-secretssoftonic2.6.91 of 1See more

sealed-secrets softonic 2.6.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,516
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

2,514
gloo-meshsolo-gloo-mesh1.1.21 of 1See more

gloo-mesh solo-gloo-mesh 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/gloo-mesh/gloo-mesh:1.1.2a4011eae6a0b
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0

Open the chart page →

3,267
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

97,304
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

3,304
spire-identity-exchangespiffeVerified publisher0.2.21 of 3See more

spire-identity-exchange spiffe 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,442
spinnakerspinnakerVerified publisher2.2.131 of 4See more

spinnaker spinnaker 2.2.13

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
golang.org/x/oauth2@v0.0.0-20190402181905-9f3314589c9a
0.27.0

Open the chart page →

6,877
ocean-admission-controllerspot1.0.31 of 3See more

ocean-admission-controller spot 1.0.3

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

773
ocean-vpaspot1.0.71 of 4See more

ocean-vpa spot 1.0.7

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

1,195
spotinst-ocean-network-clientspot1.0.01 of 1See more

spotinst-ocean-network-client spot 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

61,788
airflowsqream-chartsVerified publisher1.17.01 of 4See more

airflow sqream-charts 1.17.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus/statsd-exporter:v0.27.29ed70604d941
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

1,880
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

2,425
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
golang.org/x/oauth2@v0.2.0
0.27.0

Open the chart page →

68,698
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

3,097
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

28,532
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0

Open the chart page →

2,089
k8scostoptimizerstakaterVerified publisher0.0.51 of 1See more

k8scostoptimizer stakater 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

1,409
konfiguratorstakaterVerified publisher0.1.391 of 1See more

konfigurator stakater 0.1.39

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
stakater/konfigurator:v0.1.393409565b1ef5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,279
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/oauth2@v0.0.0-20191122200657-5d9234df094c
0.27.0

Open the chart page →

2,854
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,174
vaultstakaterVerified publisher0.8.42 of 2See more

vault stakater 0.8.4

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
hashicorp/vault-k8s:0.14.0aff47b5ba39c
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

5,872
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,565
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

6,679

Container images carrying it

2,030 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/oauth2@v0.19.0
0.27.0
1
ghcr.io/kyverno/policy-reporter:2.14.1e74c6bf33d1b
golang.org/x/oauth2@v0.6.0
0.27.0
1
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/oauth2@v0.19.0
0.27.0
1
ghcr.io/lavanet/lava/lavap:v2.5.089028adefcff
golang.org/x/oauth2@v0.16.0
0.27.0
1
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/oauth2@v0.4.0
0.27.0
1
ghcr.io/loft-sh/central-hostpath-mapper:0.2.9fa6dba122171
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/oauth2@v0.9.0
0.27.0
1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/oauth2@v0.17.0
0.27.0
1
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
golang.org/x/oauth2@v0.20.0
0.27.0
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
golang.org/x/oauth2@v0.11.0
0.27.0
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
golang.org/x/oauth2@v0.3.0
0.27.0
1
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
golang.org/x/oauth2@v0.11.0
0.27.0
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/middleware-labs/mw-lang-detector:0.1.2a4776aa2a56b
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
golang.org/x/oauth2@v0.25.0
0.27.0
1
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/oauth2@v0.5.0
0.27.0
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
golang.org/x/oauth2@v0.20.0
0.27.0
1
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/muhmmadayan/fake-network-operator:0.1.03806b1fd4a4b
golang.org/x/oauth2@v0.22.0
0.27.0
1
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/nefelim4ag/k8s-ondemand-proxy:0.0.2078b25d48cf7
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.