StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,633
of 17,792 indexed, latest versions
Container images
2,030
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,633 of 17,792 indexed charts deploy, on 2,030 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,030
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,633 by stars
ChartLatestAffected imagesRadar Score
altinity-clickhouse-operatorslamdev0.1.22 of 2See more

altinity-clickhouse-operator slamdev 0.1.2

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.20.08f0f582d41f0
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
altinity/metrics-exporter:0.20.01a46d104406d
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

6,420
external-secrets-operatorslamdev0.0.151 of 1See more

external-secrets-operator slamdev 0.0.15

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
slamdev/external-secrets-operator:0.0.8855f6625dda4
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,301
smallest-self-hostsmallest-self-hostVerified publisher0.2.26 of 12See more

smallest-self-host smallest-self-host 0.2.2

6 of the 12 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.74.06b3f6d8b4c0a
golang.org/x/oauth2@v0.19.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/oauth2@v0.18.0
0.27.0
registry.k8s.io/nfd/node-feature-discovery:v0.16.619ebca8b3804
golang.org/x/oauth2@v0.17.0
0.27.0
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

7,705
artifact-hubsoftonic1.19.04 of 8See more

artifact-hub softonic 1.19.0

4 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/trivy:0.43.1944a04445179
golang.org/x/oauth2@v0.7.0
0.27.0
artifacthub/hub:v1.19.0111918d8c399
golang.org/x/oauth2@v0.21.0
0.27.0
artifacthub/scanner:v1.19.0323d026e78c3
golang.org/x/oauth2@v0.16.0
0.27.0
artifacthub/tracker:v1.19.06596c8c4d955
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

14,569
gcp-quota-exportersoftonic2.0.21 of 1See more

gcp-quota-exporter softonic 2.0.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0

Open the chart page →

2,644
node-policy-webhooksoftonic0.1.101 of 1See more

node-policy-webhook softonic 0.1.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
softonic/node-policy-webhook:0.1.2ab6098c04a53
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,591
gloosolo-gloo-edge0.0.0-fork3 of 5See more

gloo solo-gloo-edge 0.0.0-fork

3 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/solo-io/certgen:0.0.0-forkb17a8c7d1f32
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

9,256
sp-otel-collectorsp-otel-collectorVerified publisher1.1.61 of 1See more

sp-otel-collector sp-otel-collector 1.1.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
golang.org/x/oauth2@v0.9.0
0.27.0

Open the chart page →

2,032
sql-operatorsql-operatorOfficialVerified publisher0.11.21 of 1See more

sql-operator sql-operator 0.11.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/stenic/sql-operator:1.13.2f4324baa2aad
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,594
splunk-operatorstakaterVerified publisher0.0.61 of 2See more

splunk-operator stakater 0.0.6

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
splunk/splunk-operator:2.0.0c4e0d3146226
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

11,459
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ipfs/kubo:v0.24.0e3de33bd746b
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

4,701
mayastorstartechnicaVerified publisher0.2.01 of 13See more

mayastor startechnica 0.2.0

1 of the 13 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

4,369
statpingstatping0.1.141 of 1See more

statping statping 0.1.14

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,378
stornxstornxVerified publisher1.1.11 of 9See more

stornx stornx 1.1.1

1 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

11,760
stunner-gateway-operatorstunner1.1.02 of 2See more

stunner-gateway-operator stunner 1.1.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:1.1.02f8114477ba6
golang.org/x/oauth2@v0.24.0
0.27.0
l7mp/stunner-gateway-operator:1.1.0c34f7c931491
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,292
Grafanasurajwarbhe-grafana0.1.01 of 1See more

Grafana surajwarbhe-grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
surajwarbhe/grafana:v185248611e9f1
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,604
hello-appsysintelligentVerified publisher2.0.11 of 1See more

hello-app sysintelligent 2.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sysintelligent/hello-app:2.0.177fb30df847d
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

1,880
terraform-controllerterraform-controller0.0.201 of 1See more

terraform-controller terraform-controller 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
absaoss/terraform-controller:v0.0.20ad538a1285a0
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,538
goalerttokens-studioVerified publisher0.0.51 of 2See more

goalert tokens-studio 0.0.5

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
goalert/goalert:v0.32.008d57388b0cb
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,476
spa-reloadertoucanVerified publisher0.1.01 of 1See more

spa-reloader toucan 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
toucansoftware/spa-reloader:latestc187b1fba501
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,245
traefik-hubtraefikOfficialVerified publisher4.2.01 of 1See more

traefik-hub traefik 4.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

3,171
atlantistrozz3.12.111 of 1See more

atlantis trozz 3.12.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
runatlantis/atlantis:v0.16.145fbaf7e207c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

5,287
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

4,082
boundaryundergridVerified publisher0.1.01 of 3See more

boundary undergrid 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/boundary:0.8.1fb70bd9210ff
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0

Open the chart page →

4,965
upbot-operatorupbot-operator0.0.201 of 2See more

upbot-operator upbot-operator 0.0.20

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.28.13e5c0b053fed7
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

4,477
user-componentuser-component1.2.01 of 4See more

user-component user-component 1.2.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,313
vault-gcp-secretsvault-gcp-secrets1.19.51 of 1See more

vault-gcp-secrets vault-gcp-secrets 1.19.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

2,299
vearchvearch3.3.41 of 4See more

vearch vearch 3.3.4

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

5,022
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

5,264
vultr-ccmvultrVerified publisher1.3.01 of 1See more

vultr-ccm vultr 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
vultr/vultr-cloud-controller-manager:v0.3.01806f17d620c
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,041
waardepapierenwaardepapieren1.0.01 of 3See more

waardepapieren waardepapieren 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

8,088
waardepapieren-baliewaardepapieren-balie1.0.01 of 3See more

waardepapieren-balie waardepapieren-balie 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,880
waardepapieren-registerwaardepapieren-register1.1.01 of 4See more

waardepapieren-register waardepapieren-register 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,439
frpswenerme1.0.11 of 1See more

frps wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wener/frps:v0.37.05c92cc9e8597
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,359
wharf-ainowharf-helmVerified publisher0.1.53 of 7See more

wharf-aino wharf-helm 0.1.5

3 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

13,482
wharf-cmdwharf-helmVerified publisher0.3.31 of 1See more

wharf-cmd wharf-helm 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

3,435
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

7,960
external-monitoringwiremindVerified publisher0.3.01 of 1See more

external-monitoring wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

1,300
kubemodwiremindVerified publisher0.1.51 of 2See more

kubemod wiremind 0.1.5

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.13.0cadca39288ad
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

3,030
db-backup-retentionwjentner-chartsVerified publisher1.1.01 of 1See more

db-backup-retention wjentner-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/wjentner/k8s-db-backup-retention:v1.1.08027bb46d1f4
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

898
workflows-informerworkflows-informerVerified publisher0.4.41 of 1See more

workflows-informer workflows-informer 0.4.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,171
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

10,165
redis-db-assignment-operatorwyrihaximusnetVerified publisher1.0.61 of 1See more

redis-db-assignment-operator wyrihaximusnet 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/kubernetes-redis-db-assignment-operator:v1.0.831060be60bec
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,235
heistyouniqx-ossVerified publisher1.1.2091 of 1See more

heist youniqx-oss 1.1.209

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/youniqx/heist:v1.1.209c43b3a9d98ae
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

806
cloudflare-zero-trust-operatorzelic-io0.7.11 of 1See more

cloudflare-zero-trust-operator zelic-io 0.7.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/bojanzelic/cloudflare-zero-trust-operator:0.7.1f4b2dbc19a78
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

583
popeyeadnoctemVerified publisher0.3.01 of 1See more

popeye adnoctem 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,197
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,456
bootaerokube1.0.12 of 4See more

boot aerokube 1.0.1

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/aerokube/boot:1.0.13c269612053f
golang.org/x/oauth2@v0.19.0
0.27.0
quay.io/aerokube/keygen:1.0.1578934444f04
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

7,935
browser-opsaerokube2.6.71 of 1See more

browser-ops aerokube 2.6.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/aerokube/browser-ops:2.6.7807c1bb67086
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

552
moonaerokube1.1.372 of 3See more

moon aerokube 1.1.37

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aerokube/moon:1.9.17da76ca51220d
golang.org/x/oauth2@v0.20.0
0.27.0
aerokube/moon-api:1.9.176b6323e75785
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

2,472

Container images carrying it

2,030 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/stashed/stash-enterprise:v0.32.0e9bde36e34b7
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
ghcr.io/stenic/k8status:0.17.093298e03089e
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/stenic/sql-operator:1.13.2f4324baa2aad
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
golang.org/x/oauth2@v0.15.0
0.27.0
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
golang.org/x/oauth2@v0.18.0
0.27.0
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
golang.org/x/oauth2@v0.18.0
0.27.0
1
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
golang.org/x/oauth2@v0.14.0
0.27.0
1
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
golang.org/x/oauth2@v0.18.0
0.27.0
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0
1
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0
1
ghcr.io/taskmedia/kubectl-gpg-ncftp:main0fb2b5584f7c
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/tikalk/resource-manager:latest7f21d50e69cb
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
golang.org/x/oauth2@v0.20.0
0.27.0
1
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
golang.org/x/oauth2@v0.13.0
0.27.0
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/twin/lighthouse:v0.0.45aeda2ea2ba2
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/usememos/memos:0.24.04723d86e6797
golang.org/x/oauth2@v0.23.0
0.27.0
1
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
golang.org/x/oauth2@v0.5.0
0.27.0
1
ghcr.io/voyagermesh/gateway-converter:v0.0.1b92123805584
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
golang.org/x/oauth2@v0.12.0
0.27.0
1
ghcr.io/wjentner/k8s-db-backup-retention:v1.1.08027bb46d1f4
golang.org/x/oauth2@v0.21.0
0.27.0
1
ghcr.io/wyrihaximusnet/kubernetes-redis-db-assignment-operator:v1.0.831060be60bec
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
1
ghcr.io/yeonghoo2/crashloop-operator:0.0.6565d1115e6bd
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
golang.org/x/oauth2@v0.10.0
0.27.0
1
ghcr.io/zalando/postgres-operator:v1.12.2d81cda253f5c
golang.org/x/oauth2@v0.8.0
0.27.0
1
ghcr.io/zeiss/natz-operator/account-server:0.9.5b380b5f17c3f
golang.org/x/oauth2@v0.26.0
0.27.0
1
ghcr.io/zeiss/natz-operator/operator:0.9.5187007974540
golang.org/x/oauth2@v0.26.0
0.27.0
1
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
golang.org/x/oauth2@v0.26.0
0.27.0
1
ghcr.io/zeiss/typhoon/typhoon-webhook:0.2.378f9b82050bc
golang.org/x/oauth2@v0.26.0
0.27.0
1
ghcr.io/zufardhiyaulhaq/frp-operator:v0.11.0cd25ee354df2
golang.org/x/oauth2@v0.12.0
0.27.0
1
mcr.microsoft.com/aks/kaito/gpu-provisioner:0.2.01204a7e948e9
golang.org/x/oauth2@v0.7.0
0.27.0
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
mcr.microsoft.com/oss/azure/aad-pod-identity/mic:v1.8.173004b93fcb74
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
mcr.microsoft.com/oss/azure/aad-pod-identity/nmi:v1.8.1777788bf38938
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
mcr.microsoft.com/oss/kubernetes-csi/csi-provisioner:v1.6.1667b1b1ea1e4
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.1.07997e0f236bc
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v5.2.0afdfa3da79df
golang.org/x/oauth2@v0.25.0
0.27.0
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v1.13.2fa8eba9843ff
golang.org/x/oauth2@v0.25.0
0.27.0
1
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
golang.org/x/oauth2@v0.24.0
0.27.0
1
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.19.0844478ebd5b8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/webhook:v2.0.0-beta86b0f7243250
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
1
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-2021.08.13.20.34-linux-amd6402aed3370fce
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.