StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,633
of 17,792 indexed, latest versions
Container images
2,030
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,633 of 17,792 indexed charts deploy, on 2,030 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,030
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,633 by stars
ChartLatestAffected imagesRadar Score
dregsydeliveryheroVerified publisher0.1.51 of 1See more

dregsy deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/oauth2@v0.0.0-20201109201403-9fd604954f58
0.27.0

Open the chart page →

2,977
labelsmanager-controllerdeliveryheroVerified publisher1.0.41 of 1See more

labelsmanager-controller deliveryhero 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,305
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/oauth2@v0.0.0-20181106182150-f42d05182288
0.27.0

Open the chart page →

7,987
snapshot-controllerdemocratic-csiVerified publisher0.3.01 of 1See more

snapshot-controller democratic-csi 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

467
permission-managerdevopstalesVerified publisher1.8.01 of 1See more

permission-manager devopstales 1.8.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,267
trivy-operatordevopstalesVerified publisher2.5.01 of 1See more

trivy-operator devopstales 2.5.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
devopstales/trivy-operator:2.575136aa7a26e
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

5,608
dnsmasqdevplayer0Verified publisher0.1.51 of 2See more

dnsmasq devplayer0 0.1.5

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

3,392
calicodevtron0.1.13 of 4See more

calico devtron 0.1.1

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

10,094
dex-serverdex-server1.19.11 of 3See more

dex-server dex-server 1.19.1

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dexidp/dex:v2.39.1-distroless43655afd1a8f
golang.org/x/oauth2@v0.11.0
0.27.0

Open the chart page →

2,246
digispoof-interfacedigispoof-interface1.0.01 of 3See more

digispoof-interface digispoof-interface 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,788
dnation-pingdnationcloud0.1.92 of 5See more

dnation-ping dnationcloud 0.1.9

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

10,470
docker-in-dockerdocker-in-docker0.0.31 of 2See more

docker-in-docker docker-in-docker 0.0.3

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/docker:24.0.2-dind1d148deae16a
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

2,585
dockyarddockyardVerified publisher0.4.01 of 1See more

dockyard dockyard 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kgma74/dockyard:0.4.0b40439329191
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,551
thermitedollarshaveclubOfficialVerified publisher0.1.171 of 1See more

thermite dollarshaveclub 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dollarshaveclub/thermite:0.0.31663cbf25fcfe
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,739
dragonfly-stackdragonflyVerified publisher0.1.23 of 7See more

dragonfly-stack dragonfly 0.1.2

3 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dragonflyoss/manager:v2.1.49c3ef7f10698d
golang.org/x/oauth2@v0.21.0
0.27.0
dragonflyoss/scheduler:v2.1.49523785c77787
golang.org/x/oauth2@v0.21.0
0.27.0
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

18,593
nydus-snapshotterdragonflyVerified publisher0.0.101 of 2See more

nydus-snapshotter dragonfly 0.0.10

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

3,669
elchi-discoveryelchi1.0.01 of 1See more

elchi-discovery elchi 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
jhonbrownn/elchi-discovery:latest8f6551ecc98c
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

638
elchi-stackelchi1.13.02 of 10See more

elchi-stack elchi 1.13.0

2 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.89.0995f17004231
golang.org/x/oauth2@v0.14.0
0.27.0
victoriametrics/victoria-metrics:v1.93.577a9815d0640
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

15,567
nexus-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

nexus-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,266
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

3,104
ipfs-clusterethereum-helm-chartsVerified publisher0.1.141 of 3See more

ipfs-cluster ethereum-helm-charts 0.1.14

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

4,633
event-exporterevent-exporterVerified publisher0.1.171 of 1See more

event-exporter event-exporter 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubestar/event-exporter:latest656606941255
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,210
events-exporterevents-exporter0.0.41 of 1See more

events-exporter events-exporter 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,135
github-actions-runner-operatorevryfs-ossVerified publisher2.8.11 of 1See more

github-actions-runner-operator evryfs-oss 2.8.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/evryfs/github-actions-runner-operator:v0.11.16b084e0bd082
golang.org/x/oauth2@v0.9.0
0.27.0

Open the chart page →

1,236
ecr-cleanupfairwinds-stableVerified publisher1.2.81 of 1See more

ecr-cleanup fairwinds-stable 1.2.8

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
danielfm/kube-ecr-cleanup-controller:0.1.1012485563b1d0
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,004
featurehubfeaturehub4.1.61 of 7See more

featurehub featurehub 4.1.6

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

8,248
federidfederidOfficialVerified publisher0.1.21 of 1See more

federid federid 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
federid/webhook:0.1.0fbfb7c6510a7
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,094
fission-corefission-chartsVerified publisher1.14.12 of 3See more

fission-core fission-charts 1.14.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
fission/fission-bundle:1.14.13fcfd8a0fa5d
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

7,107
free5gcfree5gcVerified publisher0.1.310 of 12See more

free5gc free5gc 0.1.3

10 of the 12 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/oauth2@v0.19.0
0.27.0
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/oauth2@v0.7.0
0.27.0
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
free5gc/udm:v3.4.32f68df062a50
golang.org/x/oauth2@v0.15.0
0.27.0
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

10,711
fsmfsmOfficialVerified publisher0.2.112 of 5See more

fsm fsm 0.2.11

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
flomesh/fsm-ingress-pipy:0.2.11cc39c96711c4
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
flomesh/fsm-manager:0.2.1122f849c70b25
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

4,227
memosgabe565Verified publisher0.17.01 of 1See more

memos gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/usememos/memos:0.24.04723d86e6797
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,331
dexgabibbo974.0.41 of 1See more

dex gabibbo97 4.0.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/oauth2@v0.0.0-20201203001011-0b49973bad19
0.27.0

Open the chart page →

3,398
otel-collectorgeek-cookbookVerified publisher1.2.21 of 1See more

otel-collector geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,568
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

5,088
temporalglasskubeVerified publisher0.45.2-gk.110 of 14See more

temporal glasskube 0.45.2-gk.1

10 of the 14 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/oauth2@v0.18.0
0.27.0
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
golang.org/x/oauth2@v0.20.0
0.27.0
temporalio/server:1.25.08a5798191dea
golang.org/x/oauth2@v0.20.0
0.27.0
temporalio/ui:2.30.25c2a3645d09c
golang.org/x/oauth2@v0.22.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/oauth2@v0.19.0
0.27.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/oauth2@v0.21.0
0.27.0
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/oauth2@v0.18.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

16,380
meta-monitoringgrafana1.3.01 of 2See more

meta-monitoring grafana 1.3.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

3,580
phlaregrafana0.5.41 of 1See more

phlare grafana 0.5.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/phlare:0.5.1330f990cdad9
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

2,091
armada-operatorgresearch0.7.01 of 2See more

armada-operator gresearch 0.7.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubebuilder/kube-rbac-proxy:v0.16.03c4f708c6204
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,575
carettagroundcover0.0.163 of 3See more

caretta groundcover 0.0.16

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/oauth2@v0.0.0-20220630143837-2104d58473e0
0.27.0
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

6,808
terraform-cloud-operatorhashicorpVerified publisher2.5.02 of 2See more

terraform-cloud-operator hashicorp 2.5.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/terraform-cloud-operator:2.5.0c2f78a575a8a
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/brancz/kube-rbac-proxy:v0.18.0754ab2a723c8
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

1,470
hawkhawk1.1.51 of 4See more

hawk hawk 1.1.5

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

13,704
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

4,205
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

6,985
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

16,596
honeycombhoneycomb1.9.31 of 1See more

honeycomb honeycomb 1.9.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
honeycombio/honeycomb-kubernetes-agent:2.7.448c38d0870f2
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

437
hpe-greenlake-file-csi-driverhpe-storageVerified publisher2.6.42 of 7See more

hpe-greenlake-file-csi-driver hpe-storage 2.6.4

2 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

6,194
htnn-controllerhtnnVerified publisher0.5.01 of 1See more

htnn-controller htnn 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

4,356
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

1,579
webhook-broker-chartimytech0.2.41 of 1See more

webhook-broker-chart imytech 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/optimizely/webhook-broker:v0.2.3cfc92cc2de65
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

1,253
telegraf-operatorinfluxdata1.4.01 of 1See more

telegraf-operator influxdata 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/influxdb/telegraf-operator:v1.3.11eec10ef37cc3
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

925

Container images carrying it

2,030 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r1-10-g1942553-2021.06.04.00.07-linux-amd64b32c99e7bc45
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
1
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
golang.org/x/oauth2@v0.13.0
0.27.0
1
public.ecr.aws/cloudnatix/llmariner/session-manager-agent:1.9.0b9f23db99051
golang.org/x/oauth2@v0.23.0
0.27.0
1
public.ecr.aws/cloudnatix/llmariner/session-manager-server:0.1.0-gfu-devb9537499ff9e
golang.org/x/oauth2@v0.23.0
0.27.0
1
public.ecr.aws/cloudnatix/llmariner/session-manager-server:1.9.0f24ecd37fbaa
golang.org/x/oauth2@v0.23.0
0.27.0
1
public.ecr.aws/dynatrace/dynatrace-operator:v1.3.0f68901a54664
golang.org/x/oauth2@v0.22.0
0.27.0
1
public.ecr.aws/eks-distro/kubernetes/kube-scheduler:v1.29.14-eks-1-29-lateste7e1db003e6a
golang.org/x/oauth2@v0.11.0
0.27.0
1
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
golang.org/x/oauth2@v0.0.0-20180821212333-d2e6202438be
0.27.0
1
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
1
public.ecr.aws/karpenter/controller:v0.19.3f0e5ab60b2df
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
public.ecr.aws/karpenter/controller:1.1.1fe383abf1dbc
golang.org/x/oauth2@v0.21.0
0.27.0
1
public.ecr.aws/n8h5y2v5/rad-security/rad-bootstrapper:v1.1.115ca2d500d374
golang.org/x/oauth2@v0.21.0
0.27.0
1
public.ecr.aws/n8h5y2v5/rad-security/rad-guard:v1.1.17a94d2d4aae85
golang.org/x/oauth2@v0.21.0
0.27.0
1
public.ecr.aws/n8h5y2v5/rad-security/rad-sbom:v1.1.34e97e0e7a2088
golang.org/x/oauth2@v0.22.0
0.27.0
1
public.ecr.aws/n8h5y2v5/rad-security/rad-sync:v1.1.1514f3dfbc0225
golang.org/x/oauth2@v0.21.0
0.27.0
1
public.ecr.aws/n8h5y2v5/rad-security/rad-watch:v1.1.25b9a7d6bc2a0c
golang.org/x/oauth2@v0.21.0
0.27.0
1
public.ecr.aws/neuron/neuron-device-plugin:2.23.30.075a6d5ce3bd3
golang.org/x/oauth2@v0.13.0
0.27.0
1
public.ecr.aws/neuron/neuron-scheduler:2.23.30.04cd274463e6b
golang.org/x/oauth2@v0.13.0
0.27.0
1
public.ecr.aws/opslevel/kubectl-opslevel:v2024.9.571697b5ff713
golang.org/x/oauth2@v0.19.0
0.27.0
1
public.ecr.aws/optimizely/webhook-broker:v0.2.3cfc92cc2de65
golang.org/x/oauth2@v0.22.0
0.27.0
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
golang.org/x/oauth2@v0.8.0
0.27.0
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
golang.org/x/oauth2@v0.18.0
0.27.0
1
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
golang.org/x/oauth2@v0.24.0
0.27.0
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
public.ecr.aws/t0u0d5o5/ecr_authenticator:latest077e4e57e41c
golang.org/x/oauth2@v0.10.0
0.27.0
1
public.ecr.aws/v0r6c2e2/minio:latest08c90bd040bf
golang.org/x/oauth2@v0.24.0
0.27.0
1
quay.io/aerokube/boot:1.0.13c269612053f
golang.org/x/oauth2@v0.19.0
0.27.0
1
quay.io/aerokube/browser-ops:2.6.7807c1bb67086
golang.org/x/oauth2@v0.18.0
0.27.0
1
quay.io/aerokube/keygen:1.0.1578934444f04
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
quay.io/aerokube/moon:2.5.1a8837b00ba1c
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
quay.io/aerokube/moon-conf:2.5.19ca307b30080
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
golang.org/x/oauth2@v0.15.0
0.27.0
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
golang.org/x/oauth2@v0.23.0
0.27.0
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
golang.org/x/oauth2@v0.4.0
0.27.0
1
quay.io/argoproj/argocli:v3.5.591b9825f09a8
golang.org/x/oauth2@v0.13.0
0.27.0
1
quay.io/argoprojlabs/argocd-extension-metrics:v1.0.30d614816c4b7
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
1
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
golang.org/x/oauth2@v0.13.0
0.27.0
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
golang.org/x/oauth2@v0.2.0
0.27.0
1
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0
1
quay.io/brancz/kube-rbac-proxy:v0.15.02c7b120590cb
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
golang.org/x/oauth2@v0.10.0
0.27.0
1
quay.io/brancz/kube-rbac-proxy:v0.18.0754ab2a723c8
golang.org/x/oauth2@v0.18.0
0.27.0
1
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
golang.org/x/oauth2@v0.15.0
0.27.0
1
quay.io/cilium/operator-generic:v1.15.1819c7281f5a4
golang.org/x/oauth2@v0.15.0
0.27.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.