StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,633
of 17,803 indexed, latest versions
Container images
2,030
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,633 of 17,803 indexed charts deploy, on 2,030 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,030
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,633 by stars
ChartLatestAffected imagesRadar Score
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

8,492
nfs-servertranhailongVerified publisher0.1.21 of 1See more

nfs-server tranhailong 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tranhailong/nfs-server:4.2-2-gcsfuse028662749be2
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

2,331
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

2,489
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

4,816
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,520
monitorortrozz0.0.11 of 1See more

monitoror trozz 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
monitoror/monitoror:44b88edcf51ff
golang.org/x/oauth2@v0.0.0-20181106182150-f42d05182288
0.27.0

Open the chart page →

3,110
clickhouse-operatortruefoundryVerified publisher0.1.12 of 3See more

clickhouse-operator truefoundry 0.1.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.23.34baec90b20cd
golang.org/x/oauth2@v0.8.0
0.27.0
altinity/metrics-exporter:0.23.32912a6c15b44
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,432
tfy-inferentia-operatortruefoundryVerified publisher0.2.83 of 3See more

tfy-inferentia-operator truefoundry 0.2.8

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/kubernetes/kube-scheduler:v1.29.14-eks-1-29-lateste7e1db003e6a
golang.org/x/oauth2@v0.11.0
0.27.0
public.ecr.aws/neuron/neuron-device-plugin:2.23.30.075a6d5ce3bd3
golang.org/x/oauth2@v0.13.0
0.27.0
public.ecr.aws/neuron/neuron-scheduler:2.23.30.04cd274463e6b
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

2,926
tfy-kservetruefoundryVerified publisher0.1.11 of 2See more

tfy-kserve truefoundry 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kserve/kserve-controller:v0.10.022ff858b57c1
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

1,178
tfy-llm-gateway-infratruefoundryVerified publisher0.2.102 of 3See more

tfy-llm-gateway-infra truefoundry 0.2.10

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.23.774315beb57db
golang.org/x/oauth2@v0.12.0
0.27.0
altinity/metrics-exporter:0.23.7a4d7ff0c727e
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

1,210
tfy-lokitruefoundryVerified publisher0.1.62 of 2See more

tfy-loki truefoundry 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:2.9.1035b02acc6765
golang.org/x/oauth2@v0.10.0
0.27.0
grafana/promtail:2.9.1063a2e57a5b14
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

2,827
aws-eks-asg-rolling-update-handlertwin1.5.01 of 1See more

aws-eks-asg-rolling-update-handler twin 1.5.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
twinproduction/aws-eks-asg-rolling-update-handler:v1.7.08f38c206972e
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,119
lighthousetwin1.0.21 of 1See more

lighthouse twin 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/twin/lighthouse:v0.0.45aeda2ea2ba2
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

544
tyk-bootstraptyk-helm5.3.02 of 3See more

tyk-bootstrap tyk-helm 5.3.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/oauth2@v0.10.0
0.27.0
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,374
tyk-control-planetyk-helm5.3.02 of 7See more

tyk-control-plane tyk-helm 5.3.0

2 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/oauth2@v0.10.0
0.27.0
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,261
tyk-stacktyk-helm5.3.02 of 7See more

tyk-stack tyk-helm 5.3.0

2 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/oauth2@v0.10.0
0.27.0
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,195
typhoontyphoonVerified publisher0.2.32 of 2See more

typhoon typhoon 0.2.3

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
golang.org/x/oauth2@v0.26.0
0.27.0
ghcr.io/zeiss/typhoon/typhoon-webhook:0.2.378f9b82050bc
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

1,686
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

8,694
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

4,994
utho-app-operator-chartutho-operatorVerified publisher0.1.61 of 2See more

utho-app-operator-chart utho-operator 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
utho/utho-app-operator:0.1.46e8a690e8b7a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

491
vault-raft-snapshot-agentvault-raft-snapshot-agentVerified publisher0.6.91 of 1See more

vault-raft-snapshot-agent vault-raft-snapshot-agent 0.6.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/argelbargel/vault-raft-snapshot-agent:v0.12.5345174727a2b
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

1,266
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,520
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,538
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,441
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,441
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

4,434
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

64,741
vineyard-operatorvineyardVerified publisher0.24.22 of 2See more

vineyard-operator vineyard 0.24.2

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
golang.org/x/oauth2@v0.13.0
0.27.0
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

4,571
vm-console-proxyvm-console-proxyVerified publisher0.2.01 of 1See more

vm-console-proxy vm-console-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/kubevirt/vm-console-proxy:v0.8.08d6b4b6e99bd
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

645
vpa-managervpa-managerVerified publisher0.4.91 of 1See more

vpa-manager vpa-manager 0.4.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jcluppnow/vpa-manager:0.6.4e459d2fba277
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

491
cert-manager-webhook-vultrvultrVerified publisher1.0.01 of 1See more

cert-manager-webhook-vultr vultr 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,507
vultr-csivultrVerified publisher2.0.01 of 4See more

vultr-csi vultr 2.0.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
vultr/vultr-csi:v0.3.041d26735d437
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,353
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wallarm/kong-kubernetes-ingress-controller:2.8b55ff6cecbd5
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

70,298
kong-previewwallarmVerified publisher4.2.31 of 5See more

kong-preview wallarm 4.2.3

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,905
wallarm-ingress-rcwallarmVerified publisher4.8.42 of 2See more

wallarm-ingress-rc wallarm 4.8.4

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wallarm/ingress-controller:4.8.0-1a591b9c91570
golang.org/x/oauth2@v0.8.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,635
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wallarm/ebpf-agent:0.11.0-rc0c8920e60c726
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

2,839
consulwarjiang1.3.02 of 2See more

consul warjiang 1.3.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
golang.org/x/oauth2@v0.7.0
0.27.0
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,102
eth-validatorwateim1.4.51 of 3See more

eth-validator wateim 1.4.5

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wateim/lighthouse-launch:latest2520149ee574
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

5,123
wavefront-hpa-adapterwavefront0.2.101 of 1See more

wavefront-hpa-adapter wavefront 0.2.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,692
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

5,496
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

11,199
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

6,293
azure-keyvault-exporterwebdevopsVerified publisher1.0.121 of 1See more

azure-keyvault-exporter webdevops 1.0.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
webdevops/azure-keyvault-exporter:24.9.1f333704ecd60
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

801
azure-scheduledevents-managerwebdevopsVerified publisher1.0.171 of 1See more

azure-scheduledevents-manager webdevops 1.0.17

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
webdevops/azure-scheduledevents-manager:24.9.0-kubernetes7acd46a8a972
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,124
kube-pool-managerwebdevopsVerified publisher1.0.161 of 1See more

kube-pool-manager webdevops 1.0.16

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
webdevops/kube-pool-manager:24.9.04fad7e14ad67
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

499
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,563
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,127
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

5,007
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ubercadence/server:0.23.22ac5491d13bb
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

10,148
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datawire/emissary:3.12.21f67a1292d2a
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

72,845

Container images carrying it

2,030 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/jetstack/cert-manager-webhook:v1.10.164121721c665
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
1
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
golang.org/x/oauth2@v0.23.0
0.27.0
1
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/cert-manager-webhook:v1.12.0ec4306b243d9
golang.org/x/oauth2@v0.5.0
0.27.0
1
quay.io/jetstack/cert-manager-webhook:v1.14.5ef419261a209
golang.org/x/oauth2@v0.15.0
0.27.0
1
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
golang.org/x/oauth2@v0.19.0
0.27.0
1
quay.io/kiali/kiali-operator:v2.32.096c5264d54ab
golang.org/x/oauth2@v0.22.0
0.27.0
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/oauth2@v0.10.0
0.27.0
1
quay.io/kube-ops/loki:2.2.14fbd63194674
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
1
quay.io/kube-ops/promtail:2.2.134de6387233b
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
golang.org/x/oauth2@v0.13.0
0.27.0
1
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
golang.org/x/oauth2@v0.5.0
0.27.0
1
quay.io/kubermatic/operating-system-manager:v1.3.010081473da43
golang.org/x/oauth2@v0.7.0
0.27.0
1
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/kubernetes-multicluster/kubefed:v0.10.0c4635c95730e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/kubevirt/kubemacpool:v0.45.0eebb65b8a12c
golang.org/x/oauth2@v0.13.0
0.27.0
1
quay.io/kubevirt/vm-console-proxy:v0.8.08d6b4b6e99bd
golang.org/x/oauth2@v0.26.0
0.27.0
1
quay.io/metallb/controller:v0.10.221164241c045
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/metallb/controller:v0.14.4bbef1ee3e7d3
golang.org/x/oauth2@v0.18.0
0.27.0
1
quay.io/metallb/speaker:v0.14.437611bde45a2
golang.org/x/oauth2@v0.18.0
0.27.0
1
quay.io/metallb/speaker:v0.10.258cb99053bb3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/minio/csi-provisioner7b5c070ec70d
golang.org/x/oauth2@v0.5.0
0.27.0
1
quay.io/minio/csi-resizer819f68a4daf7
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
quay.io/minio/directpv:v4.0.84560083eb77d
golang.org/x/oauth2@v0.6.0
0.27.0
1
quay.io/minio/minio:RELEASE.2023-12-20T01-00-02Z5702ea361420
golang.org/x/oauth2@v0.15.0
0.27.0
1
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
golang.org/x/oauth2@v0.16.0
0.27.0
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
1
quay.io/minio/minio:RELEASE.2024-06-04T19-20-08Zc6b68f158628
golang.org/x/oauth2@v0.21.0
0.27.0
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
golang.org/x/oauth2@v0.1.0
0.27.0
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
golang.org/x/oauth2@v0.6.0
0.27.0
1
quay.io/mittwald/harbor-operator:v1.6.365a38180e27a
golang.org/x/oauth2@v0.19.0
0.27.0
1
quay.io/mittwald/kubernetes-replicator:v2.10.0b79e77d421d0
golang.org/x/oauth2@v0.10.0
0.27.0
1
quay.io/mittwald/kubernetes-replicator:v2.9.1baf5f784398b
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
quay.io/mittwald/kubernetes-secret-generator:v3.4.1465b8e6d0462
golang.org/x/oauth2@v0.21.0
0.27.0
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/oauth2-proxy/oauth2-proxy:v7.7.09ed7eaf72050
golang.org/x/oauth2@v0.23.0
0.27.0
1
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/open-cluster-management/cluster-proxy:v0.12.035f9c3ad644a
golang.org/x/oauth2@v0.10.0
0.27.0
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
quay.io/openshift/origin-cli:4.66722d5041b47
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.