StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,633
of 17,803 indexed, latest versions
Container images
2,030
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,633 of 17,803 indexed charts deploy, on 2,030 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,030
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,633 by stars
ChartLatestAffected imagesRadar Score
lokikube-opsVerified publisher1.7.31 of 1See more

loki kube-ops 1.7.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/kube-ops/loki:2.2.14fbd63194674
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0

Open the chart page →

2,653
promtailkube-opsVerified publisher1.5.11 of 2See more

promtail kube-ops 1.5.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/kube-ops/promtail:2.2.134de6387233b
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0

Open the chart page →

4,158
kubereportkubereport1.1.01 of 1See more

kubereport kubereport 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesuite/kubereport:latest0262424ee702
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,120
scrutinykubernetes-homelab-helm-chartsVerified publisher0.2.21 of 3See more

scrutiny kubernetes-homelab-helm-charts 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/influxdb:2.8571eb4514977
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

5,588
brudi-operatorkubernetes-replicator0.2.31 of 1See more

brudi-operator kubernetes-replicator 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

3,632
harbor-operatorkubernetes-replicator1.6.31 of 1See more

harbor-operator kubernetes-replicator 1.6.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/mittwald/harbor-operator:v1.6.365a38180e27a
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

1,205
kubernetes-secret-generatorkubernetes-replicator3.4.11 of 1See more

kubernetes-secret-generator kubernetes-replicator 3.4.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-secret-generator:v3.4.1465b8e6d0462
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

855
kubernetesweeklykubernetesweekly2.1.01 of 1See more

kubernetesweekly kubernetesweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
zufardhiyaulhaq/kubernetesweekly:v2.1.0a287ada277c6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,489
kube-secrets-exporterkube-secrets-exporter0.1.01 of 1See more

kube-secrets-exporter kube-secrets-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/dcristobalhmad/kube-secrets-exporter:latesta9043737cb73
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

544
api-serverkubeshop0.11.161 of 2See more

api-server kubeshop 0.11.16

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeshop/testkube-api-server:0.11.160ad97f07a78b
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

3,550
kusk-gatewaykubeshop0.0.651 of 2See more

kusk-gateway kubeshop 0.0.65

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeshop/kusk-gateway:v1.5.48b5bfd57a3ce
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0

Open the chart page →

1,622
kusk-gateway-apikubeshop0.1.282 of 2See more

kusk-gateway-api kubeshop 0.1.28

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeshop/kusk-gateway-api:v1.5.4126c713cf7d8
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
kubeshop/kusk-gateway-api-websocket:v1.5.43b4f8345ca5c
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0

Open the chart page →

2,308
testkube-operatorkubeshop2.1.1542 of 3See more

testkube-operator kubeshop 2.1.154

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeshop/kube-webhook-certgen:0.0.7866827c379ae
golang.org/x/oauth2@v0.26.0
0.27.0
kubeshop/testkube-operator:2.1.154def0d0f0d4ab
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

1,019
cloudnative-pgkube-site-follower0.23.01 of 1See more

cloudnative-pg kube-site-follower 0.23.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

909
apisix-ingress-controllerkubesphereVerified publisher0.8.01 of 2See more

apisix-ingress-controller kubesphere 0.8.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apache/apisix-ingress-controller:1.3.0412f92cde0b3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,410
fluentbit-operatorkubesphereVerified publisher0.1.01 of 2See more

fluentbit-operator kubesphere 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/fluentbit-operator:v0.9.0b87db3c57cb3
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,902
gitlabkubesphereVerified publisher4.2.34 of 17See more

gitlab kubesphere 4.2.3

4 of the 17 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:alpine-v13.2.1fd7e5dfb9f30
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

38,190
harborkubesphereVerified publisher1.9.37 of 11See more

harbor kubesphere 1.9.3

7 of the 11 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
goharbor/chartmuseum-photon:v2.5.36ab3ca28e9e5
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
goharbor/harbor-core:v2.5.386bf3031f4a7
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

17,855
pvc-autoresizerkubesphereVerified publisher0.1.01 of 1See more

pvc-autoresizer kubesphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/pvc-autoresizer:v0.19a18a16c7b87
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,563
storageclass-accessorkubesphereVerified publisher0.1.01 of 1See more

storageclass-accessor kubesphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/storageclass-accessor:v0.1.1eac8f273a9b6
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

1,510
chaos-meshkubesphere-stable2.5.13 of 3See more

chaos-mesh kubesphere-stable 2.5.1

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

8,583
cni-hostnickubesphere-stable0.1.01 of 1See more

cni-hostnic kubesphere-stable 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,444
cranekubesphere-stable0.5.23 of 3See more

crane kubesphere-stable 0.5.2

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gocrane/crane-scheduler:0.0.239ba6d11b2079
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gocrane/crane-scheduler-controller:0.1.23a2d7e60576f9
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gocrane/craned:v0.5.1a1400909118c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

8,904
csi-qingcloudkubesphere-stable1.4.05 of 6See more

csi-qingcloud kubesphere-stable 1.4.0

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0

Open the chart page →

12,448
deepflowkubesphere-stable6.2.6062 of 8See more

deepflow kubesphere-stable 6.2.606

2 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
golang.org/x/oauth2@v0.4.0
0.27.0
grafana/grafana:9.5.239c849cebccc
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

18,476
edgemeshkubesphere-stable0.1.02 of 2See more

edgemesh kubesphere-stable 0.1.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubeedge/edgemesh-agent:latest460c6061b608
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
kubeedge/edgemesh-server:latesta437cf5ec0ae
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

4,135
fpga-operatorkubesphere-stable2.7.41 of 7See more

fpga-operator kubesphere-stable 2.7.4

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
inaccel/reef:latestc967218739f3
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

5,759
iomeshkubesphere-stable1.1.019 of 25See more

iomesh kubesphere-stable 1.1.0

19 of the 25 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.1.0d86dab5611a7
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
iomesh/blockdevice-monitor-prober:v0.1.0584dbe19db7e
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
iomesh/csi-driver:v2.7.25d3f9bf9240b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
iomesh/csi-snapshotter:v6.2.2becc53e25b96
golang.org/x/oauth2@v0.1.0
0.27.0
iomesh/deck:v0.1.0a31e26b6ae22
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/deck-plugin-iomesh:v0.1.00b13bf217110
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/localpv-manager:v0.2.0f13deacac3f4
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
iomesh/node-disk-exporter:1.8.0f03148764f38
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/node-disk-manager:1.8.0002c4b92fd34
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/node-disk-operator:1.8.0f6c76380db34
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/operator:v1.1.060081c9b2f52
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/post-delete-hook:v1.1.0eea5651f3270
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
golang.org/x/oauth2@v0.1.0
0.27.0
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/oauth2@v0.4.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/oauth2@v0.5.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

49,027
IOMeshkubesphere-stable1.2.019 of 25See more

IOMesh kubesphere-stable 1.2.0

19 of the 25 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
iomesh/blockdevice-monitor-prober:v0.2.1026a1d87f6e9
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
iomesh/csi-driver:v2.8.01a151f602451
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
iomesh/csi-snapshotter:v6.2.2becc53e25b96
golang.org/x/oauth2@v0.1.0
0.27.0
iomesh/deck:v0.2.0282d6c419ed3
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/deck-plugin-iomesh:v0.2.0df149e4ab39f
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/localpv-manager:v0.2.0f13deacac3f4
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
iomesh/node-disk-exporter:1.8.0f03148764f38
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/node-disk-manager:1.8.0-2292ad270082e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
iomesh/operator:v1.2.0ba4dd6be7e59
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/post-delete-hook:v1.2.0e3b92f838f4b
golang.org/x/oauth2@v0.13.0
0.27.0
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
golang.org/x/oauth2@v0.1.0
0.27.0
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/oauth2@v0.4.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/oauth2@v0.5.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

46,717
pulsarkubesphere-stable2.7.132 of 3See more

pulsar kubesphere-stable 2.7.13

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0

Open the chart page →

86,937
cni-hostnickubesphere-testVerified publisher0.1.01 of 1See more

cni-hostnic kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,444
csi-neonsankubesphere-testVerified publisher1.3.05 of 6See more

csi-neonsan kubesphere-test 1.3.0

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0

Open the chart page →

18,542
csi-qingcloudkubesphere-testVerified publisher1.4.05 of 6See more

csi-qingcloud kubesphere-test 1.4.0

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0

Open the chart page →

12,448
online-boutiquekubesphere-testVerified publisher0.1.04 of 11See more

online-boutique kubesphere-test 0.1.0

4 of the 11 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

26,080
openelbkubesphere-testVerified publisher0.2.42 of 2See more

openelb kubesphere-test 0.2.4

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.4.4ed7311a0f9e4
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

4,337
porterkubesphere-testVerified publisher0.2.21 of 2See more

porter kubesphere-test 0.2.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/porter:v0.4.38d1ed5ee1d2e
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,792
snapshot-controllerkubesphere-testVerified publisher0.2.01 of 1See more

snapshot-controller kubesphere-test 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0

Open the chart page →

2,220
kubestellar-consolekubestellar-consoleVerified publisher0.3.412 of 2See more

kubestellar-console kubestellar-console 0.3.41

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.32.47e1e7d5b7a96
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/kubestellar/console:v0.3.41457cfc94b4da
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

4,614
kubestellar-uikubestellaruiVerified publisher0.1.11 of 4See more

kubestellar-ui kubestellarui 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
mavrick1/kubestellar-b:latest45ca0429a1d4
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

5,068
kube-workload-restarterkube-workload-restarterVerified publisher0.0.41 of 1See more

kube-workload-restarter kube-workload-restarter 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
andreacioni/kube-workload-restarter:0.0.242938b310090a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,815
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.45 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

5 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/kubiyabot/kubiya-operator:runner_v26bf945565865
golang.org/x/oauth2@v0.22.0
0.27.0
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
golang.org/x/oauth2@v0.10.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

20,515
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

3,481
kuperatorkusionstackVerified publisher0.7.41 of 1See more

kuperator kusionstack 0.7.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kusionstack/kuperator:v0.7.4d2f72ae1d2f2
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

980
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

59,153
operatingkusionstackVerified publisher0.5.11 of 1See more

operating kusionstack 0.5.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kusionstack/operating:v0.5.0c28bd96b986b
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,881
sample-operatorkusionstackVerified publisher0.1.21 of 1See more

sample-operator kusionstack 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
chaerr/kridge:demo-operator-v0.1.266833deec017
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

2,515
dynatrace-operatorkvalitetsitVerified publisher1.3.01 of 1See more

dynatrace-operator kvalitetsit 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.3.0f68901a54664
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

1,320
krakendkvalitetsitVerified publisher0.0.31 of 1See more

krakend kvalitetsit 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

1,518
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

16,686
metadockvalitetsitVerified publisher0.0.72 of 2See more

metadoc kvalitetsit 0.0.7

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-app:maine89e351733ad
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0

Open the chart page →

4,033

Container images carrying it

2,030 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/cilium/tetragon:v1.1.096fac2482898
golang.org/x/oauth2@v0.17.0
0.27.0
1
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
1
quay.io/cilium/tetragon-operator:v0.8.34ab8e6604204
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0
1
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/oauth2@v0.15.0
0.27.0
1
quay.io/evryfs/github-actions-runner-operator:v0.11.16b084e0bd082
golang.org/x/oauth2@v0.9.0
0.27.0
1
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
golang.org/x/oauth2@v0.8.0
0.27.0
1
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
1
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
golang.org/x/oauth2@v0.4.0
0.27.0
1
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
golang.org/x/oauth2@v0.4.0
0.27.0
1
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
golang.org/x/oauth2@v0.4.0
0.27.0
1
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
golang.org/x/oauth2@v0.4.0
0.27.0
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
golang.org/x/oauth2@v0.9.0
0.27.0
1
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
golang.org/x/oauth2@v0.4.0
0.27.0
1
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
golang.org/x/oauth2@v0.3.0
0.27.0
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
golang.org/x/oauth2@v0.23.0
0.27.0
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0
1
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0
1
quay.io/influxdb/telegraf-operator:v1.3.11eec10ef37cc3
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jcluppnow/vpa-manager:0.6.4e459d2fba277
golang.org/x/oauth2@v0.21.0
0.27.0
1
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
golang.org/x/oauth2@v0.23.0
0.27.0
1
quay.io/jetstack/cert-manager-cainjector:v1.14.54ffda7facb4d
golang.org/x/oauth2@v0.15.0
0.27.0
1
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
1
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-cainjector:v1.12.0e0a5b06b231c
golang.org/x/oauth2@v0.5.0
0.27.0
1
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
1
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
golang.org/x/oauth2@v0.5.0
0.27.0
1
quay.io/jetstack/cert-manager-controller:v1.14.59c0527cab629
golang.org/x/oauth2@v0.15.0
0.27.0
1
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
golang.org/x/oauth2@v0.23.0
0.27.0
1
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
golang.org/x/oauth2@v0.12.0
0.27.0
1
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
golang.org/x/oauth2@v0.5.0
0.27.0
1
quay.io/jetstack/cert-manager-startupapicheck:v1.14.50f5b104bdd1b
golang.org/x/oauth2@v0.15.0
0.27.0
1
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
golang.org/x/oauth2@v0.23.0
0.27.0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.