StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,633
of 17,803 indexed, latest versions
Container images
2,030
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,633 of 17,803 indexed charts deploy, on 2,030 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,030
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,633 by stars
ChartLatestAffected imagesRadar Score
stakefishstakefish0.1.06 of 8See more

stakefish stakefish 0.1.0

6 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
golang.org/x/oauth2@v0.19.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.73.2706cde441321
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/oauth2@v0.18.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

20,351
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,262
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,262
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0

Open the chart page →

1,985
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
golang.org/x/oauth2@v0.0.0-20210113205817-d3ed898aa8a3
0.27.0
prom/prometheus:v2.22.2f7ffebdd428b
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
golang.org/x/oauth2@v0.0.0-20190402181905-9f3314589c9a
0.27.0

Open the chart page →

16,539
fluentd-operatorstatcan0.5.11 of 1See more

fluentd-operator statcan 0.5.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
vmware/kube-fluentd-operator:latestf028c138a5f4
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,960
ingress-istio-controllerstatcan1.4.01 of 1See more

ingress-istio-controller statcan 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0

Open the chart page →

1,584
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

6,597
prometheus-operatorstatcan0.2.22 of 7See more

prometheus-operator statcan 0.2.2

2 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/oauth2@v0.0.0-20190523182746-aaccbc9213b0
0.27.0

Open the chart page →

12,252
sidecar-terminatorstatcan1.3.51 of 1See more

sidecar-terminator statcan 1.3.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,316
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,827
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
golang.org/x/oauth2@v0.0.0-20180821212333-d2e6202438be
0.27.0

Open the chart page →

4,223
snapshot-controllerstevehipwellVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

495
snapshot-controllerstevehipwell-helm-charts-snapshot-controllerVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell-helm-charts-snapshot-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

495
sn-platform-slimstreamnative1.11.442 of 6See more

sn-platform-slim streamnative 1.11.44

2 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/oauth2@v0.6.0
0.27.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

62,314
stunner-prometheusstunner0.2.13 of 4See more

stunner-prometheus stunner 0.2.1

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
golang.org/x/oauth2@v0.21.0
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
golang.org/x/oauth2@v0.23.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

3,064
orchestratorsubstraVerified publisher8.8.01 of 3See more

orchestrator substra 8.8.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
golang.org/x/oauth2@v0.14.0
0.27.0

Open the chart page →

3,058
lingosubstratusVerified publisher0.2.11 of 1See more

lingo substratus 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

1,596
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,354
nocodbsudermanjr0.1.01 of 1See more

nocodb sudermanjr 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
nocodb/nocodb:0.84.15f9b799933aa8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,071
ingress-nginx-external-lbsuminhong1.0.02 of 2See more

ingress-nginx-external-lb suminhong 1.0.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
golang.org/x/oauth2@v0.17.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.044d1d0e9f19c
golang.org/x/oauth2@v0.17.0
0.27.0

Open the chart page →

2,094
do-operatorsupporttools0.1.71 of 2See more

do-operator supporttools 0.1.7

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
digitalocean/do-operator:v0.1.65e5deb4db76e
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0

Open the chart page →

1,063
nfs-provisionersupporttools0.11.01 of 1See more

nfs-provisioner supporttools 0.11.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
openebs/provisioner-nfs:0.11.04f41dd782761
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

2,680
push-to-k8ssupporttools1.1.21 of 1See more

push-to-k8s supporttools 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cube8021/push-to-k8s:v1.1.21be9baf096ff
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

530
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

10,997
ingress-nginxsvtech-public-helm-charts1.0.01 of 1See more

ingress-nginx svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

1,480
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,369
synadia-serversynadiaVerified publisher1.1.101 of 2See more

synadia-server synadia 1.1.10

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,971
agentssynapse0.1.301 of 9See more

agents synapse 0.1.30

1 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

7,287
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

1,825
ccm-hcloudsyself1.0.111 of 1See more

ccm-hcloud syself 1.0.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,713
topolvmsyself1.3.01 of 1See more

topolvm syself 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

3,612
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,876
promtailt3n1.0.01 of 1See more

promtail t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,828
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,492
paperless-ngx-backuptaskmediaVerified publisher1.1.01 of 1See more

paperless-ngx-backup taskmedia 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/taskmedia/kubectl-gpg-ncftp:main0fb2b5584f7c
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

518
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

4,228
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,773
clickhousetemp-charts0.7.12 of 3See more

clickhouse temp-charts 0.7.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

8,707
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0

Open the chart page →

70,897
istio-ingresstemp-charts0.3.31 of 1See more

istio-ingress temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.088c6c693e67a
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0

Open the chart page →

70,842
temporaltemporal0.28.97 of 13See more

temporal temporal 0.28.9

7 of the 13 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
temporalio/admin-tools:1.22.0836af062af30
golang.org/x/oauth2@v0.4.0
0.27.0
temporalio/server:1.22.0ddeebf8bad8f
golang.org/x/oauth2@v0.4.0
0.27.0
temporalio/ui:2.16.2af9c9349708f
golang.org/x/oauth2@v0.6.0
0.27.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

21,058
teredixteredix0.0.21 of 1See more

teredix teredix 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/shaharia-lab/teredix:0.0.2ec727be4417a
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,077
gmctest-opea1.0.01 of 1See more

gmc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
opea/gmcmanager:1.0514af17c495c
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

517
local-path-provisionerth-chartsVerified publisher0.0.291 of 1See more

local-path-provisioner th-charts 0.0.29

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.299bebefa0b908
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,300
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

10,115
mc-routerthl-chartsVerified publisher0.1.01 of 1See more

mc-router thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
itzg/mc-router:1.16.1bb552b59fb53
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

1,855
monitoringthl-chartsVerified publisher0.1.17 of 10See more

monitoring thl-charts 0.1.1

7 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
grafana/loki:2.5.0f9ef133793af
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
grafana/promtail:2.4.2626900031c4e
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/prometheus:v2.34.0b37103e03399
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

18,943
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
nginx/nginx-ingress:1.11.1eb5b4fd73325
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

6,890
grafanatnh5.3.01 of 1See more

grafana tnh 5.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

3,199

Container images carrying it

2,030 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/oauth2@v0.19.0
0.27.0
1
ghcr.io/kyverno/policy-reporter:2.14.1e74c6bf33d1b
golang.org/x/oauth2@v0.6.0
0.27.0
1
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/oauth2@v0.19.0
0.27.0
1
ghcr.io/lavanet/lava/lavap:v2.5.089028adefcff
golang.org/x/oauth2@v0.16.0
0.27.0
1
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/oauth2@v0.4.0
0.27.0
1
ghcr.io/loft-sh/central-hostpath-mapper:0.2.9fa6dba122171
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/oauth2@v0.9.0
0.27.0
1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/oauth2@v0.17.0
0.27.0
1
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
golang.org/x/oauth2@v0.20.0
0.27.0
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
golang.org/x/oauth2@v0.11.0
0.27.0
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
golang.org/x/oauth2@v0.3.0
0.27.0
1
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
golang.org/x/oauth2@v0.11.0
0.27.0
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/middleware-labs/mw-lang-detector:0.1.2a4776aa2a56b
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
golang.org/x/oauth2@v0.25.0
0.27.0
1
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/oauth2@v0.5.0
0.27.0
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
golang.org/x/oauth2@v0.20.0
0.27.0
1
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/muhmmadayan/fake-network-operator:0.1.03806b1fd4a4b
golang.org/x/oauth2@v0.22.0
0.27.0
1
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/nefelim4ag/k8s-ondemand-proxy:0.0.2078b25d48cf7
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.