StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,631
of 17,803 indexed, latest versions
Container images
2,028
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,631 of 17,803 indexed charts deploy, on 2,028 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,028
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,631 by stars
ChartLatestAffected imagesRadar Score
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
eclipseaerios/iota-tangle-peerer:latest99d7ff18d416
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

13,613
llo-apieclipse-aeriosVerified publisher1.0.01 of 1See more

llo-api eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
eclipseaerios/llo-api:1.2.0ab7a04182191
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

931
llo-docker-operatoreclipse-aeriosVerified publisher1.0.02 of 2See more

llo-docker-operator eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
eclipseaerios/llo-docker-operator:1.1.2d7ec28bfe735
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,193
llo-k8seclipse-aeriosVerified publisher1.1.02 of 2See more

llo-k8s eclipse-aerios 1.1.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,164
openfaas2eclipse-aeriosVerified publisher12.0.53 of 6See more

openfaas2 eclipse-aerios 12.0.5

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.51.24f6c47e39a90
golang.org/x/oauth2@v0.18.0
0.27.0
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
golang.org/x/oauth2@v0.24.0
0.27.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

6,688
chartecr-toke-renew0.1.51 of 1See more

chart ecr-toke-renew 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,818
grafanaedu5.3.01 of 1See more

grafana edu 5.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

3,198
prometheusedu11.6.01 of 6See more

prometheus edu 11.6.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

8,492
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,337
cert-manager-cpanel-dns-webhookegebackVerified publisher1.0.61 of 1See more

cert-manager-cpanel-dns-webhook egeback 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,292
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
golang.org/x/oauth2@v0.24.0
0.27.0
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

3,976
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,519
ejabberdejabberdVerified publisher0.1.01 of 1See more

ejabberd ejabberd 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
indevlab/ejabberd:24.12-k8s8bc689d093a7
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

903
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,329
kube-ecp-stackemqx-operator2.5.110 of 16See more

kube-ecp-stack emqx-operator 2.5.1

10 of the 16 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
emqx/ecp-main:2.5.1fa876f71e5d6
golang.org/x/oauth2@v0.22.0
0.27.0
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/oauth2@v0.22.0
0.27.0
library/telegraf:1.27507a3eecf809
golang.org/x/oauth2@v0.11.0
0.27.0
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.1e2dc5623bcdd
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

23,844
cnpg-monitoringenixVerified publisher0.3.01 of 1See more

cnpg-monitoring enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

824
kube-packetloss-exporterenixVerified publisher0.2.12 of 2See more

kube-packetloss-exporter enix 0.2.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/oauth2@v0.21.0
0.27.0
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

6,183
monitoring-proxyenixVerified publisher0.3.01 of 2See more

monitoring-proxy enix 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,971
eoapi-supporteoapiVerified publisher0.1.76 of 7See more

eoapi-support eoapi 0.1.7

6 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:10.3.38640e5038e83
golang.org/x/oauth2@v0.15.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/oauth2@v0.10.0
0.27.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/oauth2@v0.8.0
0.27.0
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/oauth2@v0.10.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/oauth2@v0.8.0
0.27.0
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

8,670
epinio-uiepinioVerified publisher1.7.21 of 1See more

epinio-ui epinio 1.7.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/oauth2@v0.0.0-20220822191816-0ebed06d0094
0.27.0

Open the chart page →

1,693
upgrade-responderepinioVerified publisher0.2.01 of 5See more

upgrade-responder epinio 0.2.0

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:10.1.50679e877ba20
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

7,383
admin-console-operatorepmdedpVerified publisher2.14.02 of 2See more

admin-console-operator epmdedp 2.14.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/admin-console-operator:2.14.090f9921d8d58
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
epamedp/edp-admin-console:2.14.0616c678ba3e7
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,309
edp-argocd-operatorepmdedpVerified publisher0.2.01 of 1See more

edp-argocd-operator epmdedp 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/edp-argocd-operator:0.2.0976a662a5e72
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,574
edp-headlampepmdedpVerified publisher0.25.01 of 1See more

edp-headlamp epmdedp 0.25.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/edp-headlamp:0.25.093417e18bb1a
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,267
edp-tekton-interceptorepmdedpVerified publisher0.2.41 of 1See more

edp-tekton-interceptor epmdedp 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/edp-tekton:0.2.4924939850655
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

1,351
jenkins-operatorepmdedpVerified publisher2.15.31 of 3See more

jenkins-operator epmdedp 2.15.3

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.15.328ef56bc0ca3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,116
perf-operatorepmdedpVerified publisher2.13.01 of 1See more

perf-operator epmdedp 2.13.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/perf-operator:2.13.0bd2079b7bfcb
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

1,114
reconcilerepmdedpVerified publisher2.12.01 of 1See more

reconciler epmdedp 2.12.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/reconciler:2.12.0d33e938b6d59
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,181
tekton-custom-taskepmdedpVerified publisher0.2.01 of 1See more

tekton-custom-task epmdedp 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/tekton-custom-task:0.2.067d896676f45
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

556
codebase-operatorepmdedp-devVerified publisher2.12.0-MDTU-DDM-SNAPSHOT.101 of 1See more

codebase-operator epmdedp-dev 2.12.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,826
gerrit-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.21 of 1See more

gerrit-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,812
jenkins-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

jenkins-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,267
keycloak-operatorepmdedp-devVerified publisher1.11.0-MDTU-DDM-SNAPSHOT.101 of 1See more

keycloak-operator epmdedp-dev 1.11.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,235
chaos-meshethereum-helm-chartsVerified publisher0.0.31 of 4See more

chaos-mesh ethereum-helm-charts 0.0.3

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

12,230
testnet-homepageethereum-helm-chartsVerified publisher0.2.31 of 1See more

testnet-homepage ethereum-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

2,688
ingressmonitorcontrollerevilgn0me0.0.51 of 1See more

ingressmonitorcontroller evilgn0me 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/evilgn0me/ingressmonitorcontroller:v0.0.50bbfa4db14b9
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

583
preview-appsevilmartians0.4.01 of 1See more

preview-apps evilmartians 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.10.0b79e77d421d0
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

625
exa-csiexa-csi-driver0.2.0-rev25 of 6See more

exa-csi exa-csi-driver 0.2.0-rev2

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v4.5.19dcd469f02bb
golang.org/x/oauth2@v0.13.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/oauth2@v0.15.0
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
golang.org/x/oauth2@v0.13.0
0.27.0
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

7,092
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.02 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:2.9.66ca6e2cd3b6f
golang.org/x/oauth2@v0.10.0
0.27.0
grafana/loki-canary:2.9.6549a40203e97
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

5,826
faasnetfaasnet0.0.41 of 5See more

faasnet faasnet 0.0.4

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
simpleidserver/faasprometheus:0.0.425e378d57d78
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

7,723
mandefactlyVerified publisher0.5.161 of 3See more

mande factly 0.5.16

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
factly/mande-server:0.34.1384d384310ef
golang.org/x/oauth2@v0.2.0
0.27.0

Open the chart page →

4,785
oom-event-generatorfairwinds-incubator0.2.21 of 1See more

oom-event-generator fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

4,656
skopeo-syncfairwinds-incubator0.3.11 of 1See more

skopeo-sync fairwinds-incubator 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/skopeo/stable:v1.134853591bd1d2
golang.org/x/oauth2@v0.9.0
0.27.0

Open the chart page →

1,743
stackdriver-metrics-adapterfairwinds-incubator0.3.01 of 1See more

stackdriver-metrics-adapter fairwinds-incubator 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/gke-release/custom-metrics-stackdriver-adapter:v0.13.1-gke.06937c0a9b203
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

1,765
fake-network-operatorfake-network-operatorVerified publisher0.1.01 of 1See more

fake-network-operator fake-network-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/muhmmadayan/fake-network-operator:0.1.03806b1fd4a4b
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

502
farm-observabilityfarm-observabilityOfficialVerified publisher0.27.21 of 18See more

farm-observability farm-observability 0.27.2

1 of the 18 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

13,428
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0

Open the chart page →

13,512
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

7,531
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

14,714
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

3,320

Container images carrying it

2,028 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/thanos/thanos:v0.17.1e362f02ed304
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
1
quay.io/thanos/thanos:v0.36.1e542959e1b36
golang.org/x/oauth2@v0.21.0
0.27.0
1
quay.io/tigera/operator:v1.20.1379efe0c2541
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
1
quay.io/tigera/operator:v1.15.1c6591da87aa8
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
1
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
golang.org/x/oauth2@v0.4.0
0.27.0
1
quay.io/youniqx/heist:v1.1.209c43b3a9d98ae
golang.org/x/oauth2@v0.21.0
0.27.0
1
registry.gitlab.com/bitspur/rock8s/easy-olm-operator:0.0.1779454fea06c
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
golang.org/x/oauth2@v0.8.0
0.27.0
1
registry.gitlab.com/bitspur/rock8s/resource-binding-operator:0.1.063cf51392ce7
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/oauth2@v0.0.0-20180724155351-3d292e4d0cdc
0.27.0
1
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
golang.org/x/oauth2@v0.8.0
0.27.0
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/oauth2@v0.8.0
0.27.0
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
golang.org/x/oauth2@v0.23.0
0.27.0
1
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
golang.org/x/oauth2@v0.22.0
0.27.0
1
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
golang.org/x/oauth2@v0.22.0
0.27.0
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
golang.org/x/oauth2@v0.7.0
0.27.0
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
golang.org/x/oauth2@v0.7.0
0.27.0
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
golang.org/x/oauth2@v0.3.0
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
golang.org/x/oauth2@v0.17.0
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
golang.org/x/oauth2@v0.7.0
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
golang.org/x/oauth2@v0.5.0
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
golang.org/x/oauth2@v0.23.0
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
golang.org/x/oauth2@v0.18.0
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
golang.org/x/oauth2@v0.24.0
0.27.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.044d1d0e9f19c
golang.org/x/oauth2@v0.17.0
0.27.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.0aaafd456bda1
golang.org/x/oauth2@v0.23.0
0.27.0
1
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
golang.org/x/oauth2@v0.10.0
0.27.0
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/kubectl:v1.32.73c5268158974
golang.org/x/oauth2@v0.23.0
0.27.0
1
registry.k8s.io/kubectl:v1.32.08ccae74fc039
golang.org/x/oauth2@v0.23.0
0.27.0
1
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/oauth2@v0.21.0
0.27.0
1
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
golang.org/x/oauth2@v0.7.0
0.27.0
1
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
golang.org/x/oauth2@v0.8.0
0.27.0
1
registry.k8s.io/kube-scheduler:v1.28.1146cf7475c8da
golang.org/x/oauth2@v0.8.0
0.27.0
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/oauth2@v0.3.0
0.27.0
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.2ec5732e28f15
golang.org/x/oauth2@v0.3.0
0.27.0
1
registry.k8s.io/metrics-server/metrics-server:v0.7.01c0419326500
golang.org/x/oauth2@v0.16.0
0.27.0
1
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
golang.org/x/oauth2@v0.16.0
0.27.0
1
registry.k8s.io/nfd/node-feature-discovery:v0.16.619ebca8b3804
golang.org/x/oauth2@v0.17.0
0.27.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.