StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,633
of 17,803 indexed, latest versions
Container images
2,030
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,633 of 17,803 indexed charts deploy, on 2,030 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,030
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,633 by stars
ChartLatestAffected imagesRadar Score
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

14,719
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

3,320
grgatefikaworks0.3.41 of 1See more

grgate fikaworks 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,080
first-matefirst-mateVerified publisher1.0.51 of 1See more

first-mate first-mate 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
chriswells0/first-mate:1.0.5f3918ec8471c
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,722
endpoint-auth-servicefiware0.1.42 of 4See more

endpoint-auth-service fiware 0.1.4

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

11,839
grafanaflagger1.7.01 of 1See more

grafana flagger 1.7.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,373
apm-hubflanksourceVerified publisher0.0.471 of 2See more

apm-hub flanksource 0.0.47

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

6,198
mission-control-tenantflanksourceVerified publisher1.0.923 of 3See more

mission-control-tenant flanksource 1.0.92

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
rancher/k3s:v1.28.2-k3s18c2599ecfca8
golang.org/x/oauth2@v0.11.0
0.27.0
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

5,724
fluent-operatorfluent-operatorVerified publisher0.1.01 of 2See more

fluent-operator fluent-operator 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/fluent-operator:v1.0.2702df77228c6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,631
flyte-depsflyte1.16.81 of 3See more

flyte-deps flyte 1.16.8

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,246
flyte-devboxflyte0.1.07 of 13See more

flyte-devbox flyte 0.1.0

7 of the 13 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinned0d5f740b4224
golang.org/x/oauth2@v0.26.0
0.27.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned697668be7893
golang.org/x/oauth2@v0.26.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned031408ec516f
golang.org/x/oauth2@v0.26.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned3502bb5aa60f
golang.org/x/oauth2@v0.26.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpadigest-pinned7405faeb7636
golang.org/x/oauth2@v0.26.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
golang.org/x/oauth2@v0.26.0
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned50831d9aaa69
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

4,671
forkliftforklift0.1.42 of 2See more

forklift forklift 0.1.4

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wuhan005/forklift:daemon4e6da210e449
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
wuhan005/forklift:controllerbfbe82d59850
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,814
maxscalefour-allportalVerified publisher4.1.161 of 3See more

maxscale four-allportal 4.1.16

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

6,611
free5gc-amffree5gc-amfVerified publisher0.1.31 of 1See more

free5gc-amf free5gc-amf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

902
free5gc-ausffree5gc-ausfVerified publisher0.1.31 of 1See more

free5gc-ausf free5gc-ausf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0

Open the chart page →

911
free5gc-chffree5gc-chfVerified publisher0.1.31 of 1See more

free5gc-chf free5gc-chf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

1,004
free5gc-nrffree5gc-nrfVerified publisher0.1.31 of 1See more

free5gc-nrf free5gc-nrf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0

Open the chart page →

919
free5gc-nssffree5gc-nssfVerified publisher0.1.31 of 1See more

free5gc-nssf free5gc-nssf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0

Open the chart page →

911
free5gc-pcffree5gc-pcfVerified publisher0.1.31 of 1See more

free5gc-pcf free5gc-pcf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0

Open the chart page →

903
free5gc-smffree5gc-smfVerified publisher0.1.31 of 1See more

free5gc-smf free5gc-smf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0

Open the chart page →

919
free5gc-udmfree5gc-udmVerified publisher0.1.31 of 1See more

free5gc-udm free5gc-udm 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
free5gc/udm:v3.4.32f68df062a50
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

911
free5gc-udrfree5gc-udrVerified publisher0.1.31 of 1See more

free5gc-udr free5gc-udr 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

919
free5gc-webuifree5gc-webuiVerified publisher0.1.31 of 1See more

free5gc-webui free5gc-webui 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,256
castsponsorskipgabe565Verified publisher0.8.11 of 1See more

castsponsorskip gabe565 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/gabe565/castsponsorskip:0.8.15f7b4c6dd299
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,381
galoygaloymoney0.34.74 of 24See more

galoy galoymoney 0.34.7

4 of the 24 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/oauth2@v0.14.0
0.27.0
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/oauth2@v0.6.0
0.27.0
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

8,730
galoy-depsgaloymoney0.10.208 of 9See more

galoy-deps galoymoney 0.10.20

8 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/oauth2@v0.15.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/oauth2@v0.15.0
0.27.0
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/oauth2@v0.15.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/oauth2@v0.15.0
0.27.0
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/oauth2@v0.8.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

12,010
monitoringgaloymoney0.12.215 of 6See more

monitoring galoymoney 0.12.21

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/oauth2@v0.23.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

5,336
galoygaloymoney20.34.74 of 24See more

galoy galoymoney2 0.34.7

4 of the 24 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/oauth2@v0.14.0
0.27.0
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/oauth2@v0.6.0
0.27.0
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

8,730
galoy-depsgaloymoney20.10.208 of 9See more

galoy-deps galoymoney2 0.10.20

8 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/oauth2@v0.15.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/oauth2@v0.15.0
0.27.0
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/oauth2@v0.15.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/oauth2@v0.15.0
0.27.0
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/oauth2@v0.8.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

12,010
monitoringgaloymoney20.12.215 of 6See more

monitoring galoymoney2 0.12.21

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/oauth2@v0.23.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

5,336
gatusgeek-cookbookVerified publisher1.1.21 of 1See more

gatus geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

1,882
maddygeek-cookbookVerified publisher3.2.01 of 1See more

maddy geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
foxcpp/maddy:v0.5.28fa2bd8f6830
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

2,630
minifluxgeek-cookbookVerified publisher5.2.01 of 2See more

miniflux geek-cookbook 5.2.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
miniflux/miniflux:2.0.36e2fb990dae74
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

2,430
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

3,243
vikunjageek-cookbookVerified publisher6.2.01 of 4See more

vikunja geek-cookbook 6.2.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
vikunja/api:0.17.18cba0520bf8c
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0

Open the chart page →

6,893
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

4,559
istiogetindataVerified publisher1.11.12 of 2See more

istio getindata 1.11.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:1.11.1c552478f8f11
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

16,880
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
litestream/litestream:0.3c5a1e1b01916
golang.org/x/oauth2@v0.11.0
0.27.0

Open the chart page →

9,136
gitanagitana1.4.01 of 1See more

gitana gitana 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ntakashi/gitana:1.4.04171ec641120
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

3,478
github-rate-limits-prometheus-exportergithub-rate-limit-prometheus-exporterVerified publisher0.2.151 of 1See more

github-rate-limits-prometheus-exporter github-rate-limit-prometheus-exporter 0.2.15

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kalgurn/grl-exporter:v3.2.0bd109b2bda38
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

896
gitlab-goproxygitlab-goproxy0.2.21 of 1See more

gitlab-goproxy gitlab-goproxy 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,332
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

2,616
prometheus-container-resource-exportergkarthiks0.3.11 of 1See more

prometheus-container-resource-exporter gkarthiks 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gkarthics/container-resource-exporter:latest6799af333e8a
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,218
glassflow-etlglassflowVerified publisher0.5.211 of 16See more

glassflow-etl glassflow 0.5.21

1 of the 16 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.108.0923eb1cfae32
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

12,422
go-file-servergo-file-server1.0.01 of 2See more

go-file-server go-file-server 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
goccx/go-file-server:latestf4b3ebea0303
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

2,222
gotwaygotwayVerified publisher0.8.01 of 1See more

gotway gotway 0.8.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,827
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0

Open the chart page →

22,704
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0

Open the chart page →

24,493
goweeklygoweekly2.0.01 of 1See more

goweekly goweekly 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
zufardhiyaulhaq/goweekly:v2.0.008dcc130fbea
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

1,229
ingress-nginxgpg-dev4.9.02 of 2See more

ingress-nginx gpg-dev 4.9.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/oauth2@v0.12.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

2,316

Container images carrying it

2,030 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/cilium/tetragon:v1.1.096fac2482898
golang.org/x/oauth2@v0.17.0
0.27.0
1
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
1
quay.io/cilium/tetragon-operator:v0.8.34ab8e6604204
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
1
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/oauth2@v0.15.0
0.27.0
1
quay.io/evryfs/github-actions-runner-operator:v0.11.16b084e0bd082
golang.org/x/oauth2@v0.9.0
0.27.0
1
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
golang.org/x/oauth2@v0.8.0
0.27.0
1
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
golang.org/x/oauth2@v0.4.0
0.27.0
1
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
golang.org/x/oauth2@v0.4.0
0.27.0
1
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
golang.org/x/oauth2@v0.4.0
0.27.0
1
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
golang.org/x/oauth2@v0.4.0
0.27.0
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
golang.org/x/oauth2@v0.9.0
0.27.0
1
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
golang.org/x/oauth2@v0.4.0
0.27.0
1
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
golang.org/x/oauth2@v0.3.0
0.27.0
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
golang.org/x/oauth2@v0.23.0
0.27.0
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0
1
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0
1
quay.io/influxdb/telegraf-operator:v1.3.11eec10ef37cc3
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jcluppnow/vpa-manager:0.6.4e459d2fba277
golang.org/x/oauth2@v0.21.0
0.27.0
1
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
golang.org/x/oauth2@v0.23.0
0.27.0
1
quay.io/jetstack/cert-manager-cainjector:v1.14.54ffda7facb4d
golang.org/x/oauth2@v0.15.0
0.27.0
1
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
1
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-cainjector:v1.12.0e0a5b06b231c
golang.org/x/oauth2@v0.5.0
0.27.0
1
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
1
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
golang.org/x/oauth2@v0.5.0
0.27.0
1
quay.io/jetstack/cert-manager-controller:v1.14.59c0527cab629
golang.org/x/oauth2@v0.15.0
0.27.0
1
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
golang.org/x/oauth2@v0.23.0
0.27.0
1
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
golang.org/x/oauth2@v0.12.0
0.27.0
1
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
golang.org/x/oauth2@v0.5.0
0.27.0
1
quay.io/jetstack/cert-manager-startupapicheck:v1.14.50f5b104bdd1b
golang.org/x/oauth2@v0.15.0
0.27.0
1
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
golang.org/x/oauth2@v0.23.0
0.27.0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.