StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,633
of 17,803 indexed, latest versions
Container images
2,030
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,633 of 17,803 indexed charts deploy, on 2,030 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,030
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,633 by stars
ChartLatestAffected imagesRadar Score
archive-analysispcp-helm-chartsVerified publisher1.0.11 of 1See more

archive-analysis pcp-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/performancecopilot/archive-analysis:latest8de11e2363fc
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,341
permission-managerpermission-manager1.0.0-seal1 of 1See more

permission-manager permission-manager 1.0.0-seal

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,267
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

15,476
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

15,476
container-agentphntom100.0.11 of 1See more

container-agent phntom 100.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
circleci/container-agent:34d8d0ae5efc3
golang.org/x/oauth2@v0.0.0-20220822191816-0ebed06d0094
0.27.0

Open the chart page →

1,974
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

4,649
kochiphntom1.1.41 of 1See more

kochi phntom 1.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
phntom/kochi:1.1.33b82358bd56e
golang.org/x/oauth2@v0.0.0-20180821212333-d2e6202438be
0.27.0

Open the chart page →

2,964
loki-stackphntom2.10.22 of 2See more

loki-stack phntom 2.10.2

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:2.4.2b3af8ead67d7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
grafana/promtail:2.4.2626900031c4e
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

5,725
npre-essentialsphntom0.1.6011 of 22See more

npre-essentials phntom 0.1.60

11 of the 22 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
grafana/promtail:2.7.0c16c710f7333
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
phntom/chartmuseum:v0.15.29242b4df9e65
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
phntom/kochi:1.1.33b82358bd56e
golang.org/x/oauth2@v0.0.0-20180821212333-d2e6202438be
0.27.0
phntom/oauth2-proxy:v7.3.48ea656a2a895
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/oauth2@v0.0.0-20220630143837-2104d58473e0
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.61.1cd7d1a82ef00
golang.org/x/oauth2@v0.2.0
0.27.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

26,899
blockmeta-servicepinaxVerified publisher0.0.31 of 1See more

blockmeta-service pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,698
substreams-sink-kvpinaxVerified publisher0.0.41 of 1See more

substreams-sink-kv pinax 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

53,858
substreams-sink-nooppinaxVerified publisher0.0.31 of 1See more

substreams-sink-noop pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

53,799
pixie-operator-chartpixie0.1.71 of 3See more

pixie-operator-chart pixie 0.1.7

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned1b6002156f56
golang.org/x/oauth2@v0.14.0
0.27.0

Open the chart page →

1,915
pixie-operator-helm2-chartpixie0.1.21 of 2See more

pixie-operator-helm2-chart pixie 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinnedf9ea8cef95ac
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

1,769
planectlplanectlVerified publisher0.7.02 of 10See more

planectl planectl 0.7.0

2 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
golang.org/x/oauth2@v0.20.0
0.27.0
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

26,407
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

11,163
tenant-namespacepnnl-miscscripts0.6.231 of 1See more

tenant-namespace pnnl-miscscripts 0.6.23

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

2,578
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

13,114
podnat-controllerpodnat-controller0.5.21 of 1See more

podnat-controller podnat-controller 0.5.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gutmensch/podnat-controller:0.5.2566979793fc4
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

984
trainingjobspolyaxon2.1.01 of 1See more

trainingjobs polyaxon 2.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
polyaxon/training-operator:2.1.0b5b29deaec9a
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

726
beylaportefaix-hub0.1.01 of 1See more

beyla portefaix-hub 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/beyla:1.3.336d07f8d276e
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

2,729
cloudflare-tunnelportefaix-hub0.4.01 of 1See more

cloudflare-tunnel portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.8.314d9c6b01b29
golang.org/x/oauth2@v0.17.0
0.27.0

Open the chart page →

1,344
prometheus-bbox-exporterportefaix-hub0.4.11 of 1See more

prometheus-bbox-exporter portefaix-hub 0.4.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/nlamirault/bbox_exporter:1.0.0f5dd1f7794c6
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

2,014
prometheus-freebox-exporterportefaix-hub0.1.11 of 1See more

prometheus-freebox-exporter portefaix-hub 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/nlamirault/freebox-exporter:1.0.02d522b664e12
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0

Open the chart page →

1,755
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

9,615
oauth2-proxypresto-loadbalancer4.3.181 of 2See more

oauth2-proxy presto-loadbalancer 4.3.18

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,965
presto-exporterpresto-loadbalancer0.0.91 of 1See more

presto-exporter presto-loadbalancer 0.0.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
garugaru/presto-exporter:cb666560e9e82d5ae36aef1e663c3d7f51cca9fc5201314c28f3
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,191
trino-exporterpresto-loadbalancer0.0.121 of 1See more

trino-exporter presto-loadbalancer 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datappeal/trino-exporter:latest325b91c2b09e
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

1,969
trino-loadbalancerpresto-loadbalancer0.3.11 of 1See more

trino-loadbalancer presto-loadbalancer 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,358
procestypecatalogusprocestypecatalogus1.1.01 of 4See more

procestypecatalogus procestypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,441
productenendienstencatalogusproductenendienstencatalogus1.0.01 of 3See more

productenendienstencatalogus productenendienstencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,520
capsule-addon-fluxcdprojectcapsuleVerified publisher0.2.01 of 1See more

capsule-addon-fluxcd projectcapsule 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/projectcapsule/capsule-addon-fluxcd:0.2.2e0baf564b706
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

547
capsule-proxyprojectcapsuleOfficialVerified publisher0.14.11 of 2See more

capsule-proxy projectcapsule 0.14.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,227
prometheus-modbus-exporterprometheus-communityVerified publisher0.1.41 of 1See more

prometheus-modbus-exporter prometheus-community 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
openenergyprojects/modbus_exporter:20230617_a14455158990f24fb25
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,209
prometheus-optimizerprometheus-optimizer0.2.221 of 1See more

prometheus-optimizer prometheus-optimizer 0.2.22

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

4,468
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

8,735
proto-component-commongroundproto-component-commonground1.0.01 of 3See more

proto-component-commonground proto-component-commonground 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,520
kspanpuckpuck0.2.41 of 1See more

kspan puckpuck 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

1,688
seashellpuckpuck1.2.01 of 1See more

seashell puckpuck 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/puckpuck/seashell:1.2ef5e31333821
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,221
pulumi-esc-csi-providerpulumi-esc-csi-provider0.1.61 of 1See more

pulumi-esc-csi-provider pulumi-esc-csi-provider 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/pulumi/pulumi-esc-csi-provider:0.1.13fb058e93502
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

823
cdmswebapppyalive-cdmswebappVerified publisher0.1.01 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sarwansharma/minio:v359d1da9385d1
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

6,702
loki-stackpyalive-cdmswebappVerified publisher2.6.52 of 4See more

loki-stack pyalive-cdmswebapp 2.6.5

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:2.5.0f9ef133793af
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
grafana/promtail:2.4.2626900031c4e
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

6,584
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

11,956
quarksquarks7.0.1+0.g5396b114 of 5See more

quarks quarks 7.0.1+0.g5396b11

4 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

18,202
quarks-statefulsetquarks0.0.1304-g4b4f2ac51 of 1See more

quarks-statefulset quarks 0.0.1304-g4b4f2ac5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,011
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:3.3.28af2de1abbdd
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

4,515
ingress-controllerqumine0.8.5001 of 1See more

ingress-controller qumine 0.8.500

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
qumine/ingress-controller:v0.8.5f2c8a2148381
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

1,533
hydraradar-baseVerified publisher0.48.01 of 1See more

hydra radar-base 0.48.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/oauth2@v0.14.0
0.27.0

Open the chart page →

1,541
kratosradar-baseVerified publisher0.43.11 of 1See more

kratos radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
oryd/kratos:v1.1.08f15006a080d
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,793
kubecostradar-baseVerified publisher1.0.03 of 7See more

kubecost radar-base 1.0.0

3 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
golang.org/x/oauth2@v0.23.0
0.27.0
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
golang.org/x/oauth2@v0.25.0
0.27.0
quay.io/prometheus/prometheus:v3.2.05888c188cf09
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

9,625

Container images carrying it

2,030 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/stashed/stash-enterprise:v0.32.0e9bde36e34b7
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
ghcr.io/stenic/k8status:0.17.093298e03089e
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/stenic/sql-operator:1.13.2f4324baa2aad
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
golang.org/x/oauth2@v0.15.0
0.27.0
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
golang.org/x/oauth2@v0.18.0
0.27.0
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
golang.org/x/oauth2@v0.18.0
0.27.0
1
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
golang.org/x/oauth2@v0.14.0
0.27.0
1
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
golang.org/x/oauth2@v0.18.0
0.27.0
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0
1
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0
1
ghcr.io/taskmedia/kubectl-gpg-ncftp:main0fb2b5584f7c
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/tikalk/resource-manager:latest7f21d50e69cb
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
golang.org/x/oauth2@v0.20.0
0.27.0
1
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
golang.org/x/oauth2@v0.13.0
0.27.0
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/twin/lighthouse:v0.0.45aeda2ea2ba2
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/usememos/memos:0.24.04723d86e6797
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
golang.org/x/oauth2@v0.5.0
0.27.0
1
ghcr.io/voyagermesh/gateway-converter:v0.0.1b92123805584
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
golang.org/x/oauth2@v0.12.0
0.27.0
1
ghcr.io/wjentner/k8s-db-backup-retention:v1.1.08027bb46d1f4
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/wyrihaximusnet/kubernetes-redis-db-assignment-operator:v1.0.831060be60bec
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
1
ghcr.io/yeonghoo2/crashloop-operator:0.0.6565d1115e6bd
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/zalando/postgres-operator:v1.12.2d81cda253f5c
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/zeiss/natz-operator/account-server:0.9.5b380b5f17c3f
golang.org/x/oauth2@v0.26.0
0.27.0
1
ghcr.io/zeiss/natz-operator/operator:0.9.5187007974540
golang.org/x/oauth2@v0.26.0
0.27.0
1
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
golang.org/x/oauth2@v0.26.0
0.27.0
1
ghcr.io/zeiss/typhoon/typhoon-webhook:0.2.378f9b82050bc
golang.org/x/oauth2@v0.26.0
0.27.0
1
ghcr.io/zufardhiyaulhaq/frp-operator:v0.11.0cd25ee354df2
golang.org/x/oauth2@v0.12.0
0.27.0
1
mcr.microsoft.com/aks/kaito/gpu-provisioner:0.2.01204a7e948e9
golang.org/x/oauth2@v0.7.0
0.27.0
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
mcr.microsoft.com/oss/azure/aad-pod-identity/mic:v1.8.173004b93fcb74
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
mcr.microsoft.com/oss/azure/aad-pod-identity/nmi:v1.8.1777788bf38938
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
mcr.microsoft.com/oss/kubernetes-csi/csi-provisioner:v1.6.1667b1b1ea1e4
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.1.07997e0f236bc
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v5.2.0afdfa3da79df
golang.org/x/oauth2@v0.25.0
0.27.0
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v1.13.2fa8eba9843ff
golang.org/x/oauth2@v0.25.0
0.27.0
1
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
golang.org/x/oauth2@v0.24.0
0.27.0
1
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.19.0844478ebd5b8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/webhook:v2.0.0-beta86b0f7243250
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
1
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-2021.08.13.20.34-linux-amd6402aed3370fce
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.